Description
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
Published: 2026-10-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

An unauthenticated PHP Object Injection flaw exists in the GDPR Framework By Data443 plugin versions up to and including 2.5.0, allowing an attacker to create serialized objects that are deserialized by the plugin. The injection permits execution of arbitrary PHP code with the privileges of the web application, leading to full remote code execution. The flaw falls under CWE-502, reflecting an insecure deserialization vulnerability.

Affected Systems

The vulnerability affects WordPress sites that have the GDPR Framework By Data443 plugin installed. All releases of the plugin through version 2.5.0 are impacted. Site owners must identify whether they are running any of these vulnerable versions.

Risk and Exploitability

With a CVSS score of 9.8 and no EPSS or KEV information, the risk assessment indicates a highly severe condition. Because the flaw is unauthenticated and driven by crafted payloads, an attacker with internet connectivity to the site can exploit it without needing credentials. No public exploitation activity is recorded, but the lack of mitigations combined with the injection barrier makes exploitation highly likely if the vulnerability remains present.

Generated by OpenCVE AI on October 6, 2026 at 11:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the GDPR Framework By Data443 plugin to the latest release that removes the object injection flaw
  • If an upgrade cannot be performed immediately, disable the plugin from the WordPress administration area or restrict its usage so that only trusted administrators can access it
  • Deploy a web application firewall or input‑validation layer that blocks or rejects crafted serialized PHP payloads from unauthenticated requests

Generated by OpenCVE AI on October 6, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
Title WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:33.072Z

Reserved: 2026-04-07T10:59:21.050Z

Link: CVE-2026-39797

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:17.631Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:52.843

Modified: 2026-10-06T11:17:26.763

Link: CVE-2026-39797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data