GDPR Framework accepts forged consent and privacy requests
The GDPR Framework before 2.4.0 does not adequately verify authorization or the data subject's identity when recording cookie-consent choices and privacy requests. An unauthenticated attacker can create forged consent records for arbitrary email addresses and flood the site's privacy-request queue with attacker-chosen entries. The public advisory does not disclose the endpoints, email or consent parameters, record functions or rate limits.
- Component
- The GDPR Framework By Data443
- Plugin slug
gdpr-framework-by-data443- Affected
- < 2.4.0
- Safe version
2.4.0- Published
- Aug 04, 2026
This CVE was published Aug 04, 2026 and is one of 1 known issue for this plugin.
Update, patch or deactivate.
Update The GDPR Framework By Data443 to 2.4.0 or later. Review consent records and privacy requests created while vulnerable, remove forged entries and independently verify a requester's identity before processing privacy actions.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L