The GDPR Framework By Data443
The GDPR Framework By Data443 provides tools for managing personal data requests and privacy-related features in WordPress.
The GDPR Framework By Data443 (gdpr-framework-by-data443) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.5.
gdpr-framework-by-data443CVE-2026-14816: GDPR Framework accepts forged consent and privacy requests
The GDPR Framework before 2.4.0 does not adequately verify authorization or the data subject's identity when recording cookie-consent choices and privacy requests. An unauthenticated attacker can create forged consent records for arbitrary email addresses and flood the site's privacy-request queue with attacker-chosen entries. The public advisory does not disclose the endpoints, email or consent parameters, record functions or rate limits.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-14816
GDPR Framework accepts forged consent and privacy requests
The GDPR Framework before 2.4.0 does not adequately verify authorization or the data subject's identity when recording cookie-consent choices and privacy requests. An unauthenticated attacker can create forged consent records for arbitrary email addresses and flood the site's privacy-request queue with attacker-chosen entries. The public advisory does not disclose the endpoints, email or consent parameters, record functions or rate limits.
|
2.4.0 |
CVE6.5
NVDPending
|