WordPress security changelog
MEDIUM CVE-2026-14816 Received

GDPR Framework accepts forged consent and privacy requests

The GDPR Framework before 2.4.0 does not adequately verify authorization or the data subject's identity when recording cookie-consent choices and privacy requests. An unauthenticated attacker can create forged consent records for arbitrary email addresses and flood the site's privacy-request queue with attacker-chosen entries. The public advisory does not disclose the endpoints, email or consent parameters, record functions or rate limits.

CVE / CNA score 6.5 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
The GDPR Framework By Data443
Plugin slug
gdpr-framework-by-data443
Affected
< 2.4.0
Safe version
2.4.0
Published
Aug 04, 2026
Weakness
CWE-284 — Improper Access Control

This CVE was published Aug 04, 2026 and is one of 1 known issue for this plugin.

Update, patch or deactivate.

Update The GDPR Framework By Data443 to 2.4.0 or later. Review consent records and privacy requests created while vulnerable, remove forged entries and independently verify a requester's identity before processing privacy actions.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Primary and upstream sources