CVE-2026-85348 PUBLISHED

GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF

Assigner: WPScan
Reserved: 03.09.2026 Published: 09.10.2026 Updated: 09.10.2026

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor Unknown
Product GDPR Data Request Form
Versions Default: unknown
  • affected from 1.5 to 1.7.1 (incl.)

Credits

  • Shikhali Jamalzade finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE