Description
The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.
Published: 2026-07-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DSGVO All in one for WP plugin is vulnerable to a missing authorization flaw in the dsgvo_reset_policy_service_func() function, which omits capability checks and nonce verification. Attackers who are authenticated with Subscriber or higher privileges can invoke this function to reset all custom privacy policy content, cookie notices, and external service policies to their default values. This compromise of configuration integrity undermines GDPR compliance and can expose the site to legal liability. The weakness is identified as a missing authorization issue (CWE‑862).

Affected Systems

The affected vendor is mlfactory, and its DSGVO All in one for WP plugin is affected in all releases up to and including version 4.9. No later versions are mentioned in the data. Sites running the plugin up to and including version 4.9 are therefore at risk.

Risk and Exploitability

The CVSS score of 4.3 reflects moderate impact, while the EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation campaigns. Attackers must be authenticated and possess at least Subscriber role privileges; based on the description, it is inferred that the most likely vector is an internal or compromised account that already has legitimate credentials. Given these conditions, organizations should treat the vulnerability with medium priority and apply the official fix promptly.

Generated by OpenCVE AI on July 29, 2026 at 12:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DSGVO All in one for WP to the latest version that enforces proper authorization checks.
  • If an upgrade cannot be performed immediately, disable the reset functionality for Subscriber and lower roles by removing the capability checks in the plugin or temporarily deactivating the plugin until a patch is applied.
  • Restrict Subscriber accounts from accessing the plugin settings and enable two‑factor authentication for all user accounts to reduce the risk of credential compromise.

Generated by OpenCVE AI on July 29, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mlfactory
Mlfactory dsgvo All In One For Wp
Wordpress
Wordpress wordpress
Vendors & Products Mlfactory
Mlfactory dsgvo All In One For Wp
Wordpress
Wordpress wordpress

Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.
Title DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mlfactory Dsgvo All In One For Wp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-09T14:39:42.090Z

Reserved: 2026-03-16T19:14:02.711Z

Link: CVE-2026-4298

cve-icon Vulnrichment

Updated: 2026-07-09T14:39:38.100Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses