Impact
The DSGVO All in one for WP plugin is vulnerable to a missing authorization flaw in the dsgvo_reset_policy_service_func() function, which omits capability checks and nonce verification. Attackers who are authenticated with Subscriber or higher privileges can invoke this function to reset all custom privacy policy content, cookie notices, and external service policies to their default values. This compromise of configuration integrity undermines GDPR compliance and can expose the site to legal liability. The weakness is identified as a missing authorization issue (CWE‑862).
Affected Systems
The affected vendor is mlfactory, and its DSGVO All in one for WP plugin is affected in all releases up to and including version 4.9. No later versions are mentioned in the data. Sites running the plugin up to and including version 4.9 are therefore at risk.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate impact, while the EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation campaigns. Attackers must be authenticated and possess at least Subscriber role privileges; based on the description, it is inferred that the most likely vector is an internal or compromised account that already has legitimate credentials. Given these conditions, organizations should treat the vulnerability with medium priority and apply the official fix promptly.
OpenCVE Enrichment