CVE-2026-4298
Deferred Deferred - Pending Action

Missing Authorization in DSGVO All in one for WP Plugin

Vulnerability report for CVE-2026-4298, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-09

Last updated on: 2026-07-09

Assigner: Wordfence

Description

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-09
Last Modified
2026-07-09
Generated
2026-07-11
AI Q&A
2026-07-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_all_in_one_dsgvo plugin to 4.9 (inc)
wp_plugin dsgvo_all_in_one to 4.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The DSGVO All in one for WP plugin for WordPress has a vulnerability called Missing Authorization in all versions up to and including 4.9. This occurs because the function dsgvo_reset_policy_service_func() does not perform capability checks or nonce verification when processing user-supplied parameters to reset plugin options.

As a result, authenticated attackers with Subscriber-level access or higher can reset all customized privacy policy content, including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies, back to their default values.

Impact Analysis

This vulnerability allows attackers with low-level authenticated access to reset all customized privacy policy settings in the plugin to default values. This can disrupt the intended privacy notices and policies on your WordPress site, potentially misleading users or removing important privacy customizations.

Since the integrity of privacy policy content is compromised, it could lead to incorrect or missing privacy information being displayed to site visitors.

Compliance Impact

This vulnerability allows authenticated attackers with Subscriber-level access and above to reset all customized privacy policy content, including cookie notices and various third-party policies, to their default values.

By resetting customized privacy policies, the plugin may no longer accurately reflect the organization's actual data handling practices, potentially leading to non-compliance with privacy regulations such as GDPR (DSGVO) which require clear and accurate privacy notices.

However, the provided information does not explicitly detail the direct impact on compliance with standards like GDPR or HIPAA.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4298. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart