← WordPress Vulnerabilities
WordPress security by component

WordPress GDPR

WordPress GDPR is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Nov 19, 2024; the highest CVE/CNA score is 7.2.

Plugin slug: wordpress-gdpr

CVE-2024-11069: WordPress GDPR: A security weakness

WordPress GDPR is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedNov 19, 2024
Safe version guidanceSee mitigation notes
Safe version
Nov 19, 2024 CVE-2024-11069
WordPress GDPR: A security weakness
WordPress GDPR is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD9.1
Nov 19, 2024 CVE-2024-10388
WordPress GDPR: Cross-site scripting
WordPress GDPR is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1