Description
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Published: 2026-07-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check when processing immediate data‑subject access requests. This flaw allows an attacker to supply a target user’s e‑mail address and trigger the full personal‑data export, exposing the name, postal address, phone number, e‑mail and comment content of that user. The vulnerability is a classic information disclosure (CWE‑200) compounded by an access‑control weakness (CWE‑284).

Affected Systems

All installations of WP DSGVO Tools (GDPR) WordPress plugin versions 3.1.39 and earlier are affected; any WordPress site that has not upgraded to 3.1.40 or later is vulnerable. The flaw exists across all deployments of the plugin through the public web surface.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low, but not negligible. The vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker can exploit the flaw simply by making an HTTP request to the subject-access-request endpoint with only be able to reach the public web interface of the site.

Generated by OpenCVE AI on July 28, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP DSGVO Tools (GDPR) to version 3.1.40 or later
  • Configure the web server or use a security plugin to restrict the subject-access-request endpoint so that only authenticated users can invoke it
  • If an immediate upgrade is not possible, disable the data‑subject access request feature in the plugin settings or remove the plugin until a patch becomes available

Generated by OpenCVE AI on July 28, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Description The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Title WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-09T14:40:56.289Z

Reserved: 2026-06-10T12:15:34.139Z

Link: CVE-2026-11869

cve-icon Vulnrichment

Updated: 2026-07-09T14:40:51.192Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses

No weakness.