CVE-2026-79324
Analyzed Analyzed - Analysis Complete

Missing Authorization in Mageplaza GDPR for Magento 2

Vulnerability report for CVE-2026-79324, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: MITRE

Description

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mageplaza gdpr to 4.2.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization issue in Mageplaza GDPR for Magento 2 through version 4.2.9. It allows remote unauthenticated attackers to delete any customer's saved address by sending a GET request to /customer/address/delete/id/{id}. The controller bypasses authentication and ownership checks because it extends the legacy Action class instead of AbstractAccount.

Detection Guidance

Check Magento 2 logs for unusual GET requests to /customer/address/delete/id/{id} without authentication. Inspect network traffic for repeated address deletion attempts targeting different IDs. Verify if Mageplaza GDPR extension version is 4.2.9 or lower.

Impact Analysis

This vulnerability can lead to unauthorized deletion of customer addresses, erasing all stored addresses by iterating through IDs. It disrupts checkout processes, affects customer PII integrity, and allows attackers to manipulate data without authentication or user interaction.

Compliance Impact

This vulnerability compromises GDPR compliance by allowing unauthorized deletion of customer data, violating principles of data integrity and access control. It may also impact HIPAA if the system handles protected health information, as unauthorized data deletion could breach confidentiality requirements.

Mitigation Strategies

Update Mageplaza GDPR extension to the latest version. Ensure the Address Delete controller extends AbstractAccount and enforces authentication and ownership checks. Replace GET requests with POST for state changes and require form keys for all actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79324. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart