CVE-2026-14816
Received Received - Intake

Unauthenticated Consent Forgery in GDPR Framework WordPress Plugin

Vulnerability report for CVE-2026-14816, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
data443 gdpr_framework to 2.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The GDPR Framework By Data443 WordPress plugin before version 2.4.0 has a flaw where it fails to properly verify authorization or the identity of users when handling cookie-consent choices and privacy requests. This allows unauthenticated attackers to create fake consent records for any email address and overload the site's privacy-request queue with arbitrary entries.

Impact Analysis

This vulnerability could allow attackers to manipulate consent records, potentially making it appear that users have given consent when they have not. It could also disrupt site operations by flooding the privacy-request queue with fake entries, causing legitimate requests to be ignored or delayed.

Compliance Impact

This vulnerability directly impacts GDPR compliance by allowing unauthorized changes to consent records, which violates GDPR's requirement for valid user consent. It could also affect HIPAA compliance if the plugin is used in healthcare contexts, as it may compromise data privacy controls.

Mitigation Strategies

Update the GDPR Framework By Data443 WordPress plugin to version 2.4.0 or later to address the authorization and identity verification issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14816. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart