Description
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Published: 2026-07-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP DSGVO Tools (GDPR) WordPress plugin versions older than 3.1.40 fails to perform an authorization check when processing an immediate data‑subject access request. This weakness allows an attacker to supply any user’s e‑mail address and trigger the export of that user’s complete personal data, including name, postal address, phone number, e‑mail address, and comment content. The vulnerability is a classic information disclosure compounded by an improper authorization flaw.

Affected Systems

Every installation of the WP DSGVO Tools (GDPR) plugin on a WordPress site that has not been updated to version 3.1.40 or later is affected. The flaw exists under the public web interface of the plugin and can be triggered by any visitor to the site.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is under 1%, revealing a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker can exploit the flaw simply by sending an HTTP request to the plugin’s subject‑access‑request endpoint with a target e‑mail address, causing the server to generate and provide a full personal data export.

Generated by OpenCVE AI on August 5, 2026 at 03:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP DSGVO Tools (GDPR) plugin to version 3.1.40 or later to fix the missing authorization check.
  • Reconfigure the web server or employ a security plugin to restrict access to the subject‑access‑request endpoint, ensuring that only authenticated users can invoke it.
  • If an immediate upgrade is not possible, disable the data‑subject access request feature in the plugin settings or remove the plugin entirely until a patch becomes available.

Generated by OpenCVE AI on August 5, 2026 at 03:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 31 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Description The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Title WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-09T14:40:56.289Z

Reserved: 2026-06-10T12:15:34.139Z

Link: CVE-2026-11869

cve-icon Vulnrichment

Updated: 2026-07-09T14:40:51.192Z

cve-icon NVD

Status : Deferred

Published: 2026-07-09T07:16:22.997

Modified: 2026-07-09T16:34:18.103

Link: CVE-2026-11869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T03:15:05Z

Weaknesses