Description
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated sensitive data exposure occurs in the Complianz GDPR plugin for WordPress versions 7.5.0 and earlier, allowing an attacker to read confidential configuration or user data without authentication. This flaw is linked to CWE‑497, indicating that the plugin exposes data that should be considered confidential. An attacker who can trigger the vulnerability can retrieve the exposed contents, compromising user privacy and potentially revealing information that could aid further attacks.

Affected Systems

The vulnerability affects WordPress installations running the Complianz plugin from vendors identified as Complianz:Complianz, specifically versions 7.5.0 and below. All WordPress sites using the plugin within this version range are potentially impacted.

Risk and Exploitability

The CVSS score of 5.3 rates this threat as moderate, while an EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no widely known or documented exploits. The likely attack vector is an unauthenticated HTTP request that triggers the plugin to expose data, with no additional authentication or privilege requirements.

Generated by OpenCVE AI on August 3, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Complianz plugin to the latest version (7.5.1 or newer).
  • If the plugin is not essential, remove it entirely from the WordPress installation.
  • Limit access to plugin configuration pages to authenticated administrators or specific user roles.

Generated by OpenCVE AI on August 3, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Complianz
Complianz complianz
Wordpress
Wordpress wordpress
Vendors & Products Complianz
Complianz complianz
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
Title WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Complianz Complianz
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-12T18:57:28.433Z

Reserved: 2026-07-22T08:53:43.312Z

Link: CVE-2026-65498

cve-icon Vulnrichment

Updated: 2026-07-23T15:55:51.128Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:43.160

Modified: 2026-07-23T16:17:51.617

Link: CVE-2026-65498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:00:04Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere