Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 24 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Legalweb
Legalweb wp Dsgvo Tools Wordpress Wordpress wordpress |
|
| Vendors & Products |
Legalweb
Legalweb wp Dsgvo Tools Wordpress Wordpress wordpress |
Tue, 24 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated attackers to permanently destroy any non-administrator user account (password randomized, username/email overwritten, roles stripped, comments anonymized, sensitive usermeta wiped) by submitting the victim's email address with `process_now=1`. The nonce required for the request is publicly available on any page containing the `[unsubscribe_form]` shortcode. | |
| Title | WP DSGVO Tools (GDPR) <= 3.1.38 - Missing Authorization to Unauthenticated Account Destruction of Non-Admin Users | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-03-24T13:18:49.435Z
Reserved: 2026-03-16T16:17:14.969Z
Link: CVE-2026-4283
Updated: 2026-03-24T13:18:44.624Z
Status : Awaiting Analysis
Published: 2026-03-24T05:16:24.343
Modified: 2026-03-24T15:53:48.067
Link: CVE-2026-4283
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:40:06Z