Impact
The GDPR Framework by Data443 WordPress plugin fails to verify the identity of the user and the authorization of the request when a cookie‑consent or privacy request is recorded. This flaw allows an unauthenticated attacker to create forged consent records for any email address and to submit an arbitrary number of entries into the site’s privacy‑request queue, potentially violating privacy regulations and disrupting normal site operation. The primary impact is the tampering of user consent data, which could be used to claim compliance where none exists, and the denial of service effect from queue flooding.
Affected Systems
WordPress plugin GDPR Framework by Data443, versions prior to 2.4.0.
Risk and Exploitability
The vulnerability can be exploited remotely via HTTP requests to the plugin’s consent and privacy‑request endpoints, which accept data with no authentication checks. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog. The lack of a CVSS score means the exact severity cannot be quantified here, but the ability for attackers to forge consent records and flood the privacy‑request queue suggests a moderate to high risk to data integrity and availability, especially for sites that rely on this plugin to manage user privacy consent.
OpenCVE Enrichment