CVE-2026-85348
Received Received - Intake

GDPR Data Request Form CSRF Vulnerability

Vulnerability report for CVE-2026-85348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: WPScan

Description

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown GDPR Data Request Form 1.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the GDPR Data Request Form WordPress plugin versions 1.5 to 1.7.1. It allows attackers to trick a site administrator into changing a plugin setting via a malicious link, such as updating the Data Protection Officer email address without proper authorization.

Detection Guidance

To detect this vulnerability, check if the GDPR Data Request Form WordPress plugin version is between 1.5 and 1.7.1. Inspect network traffic for unauthorized POST requests to plugin settings, particularly those modifying the DPO email address. Look for suspicious administrator actions triggered by external links.

Impact Analysis

An attacker could manipulate a site administrator into altering plugin settings, potentially changing the DPO email address. This could lead to unauthorized modifications, data handling disruptions, or compliance issues if the plugin manages GDPR-related requests.

Compliance Impact

This vulnerability could impact GDPR compliance by allowing unauthorized changes to data protection settings, potentially affecting how user data requests are handled. It may lead to improper data processing or disclosure, violating GDPR requirements for data protection and user rights.

Mitigation Strategies

Immediately update the GDPR Data Request Form plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Implement CSRF protection mechanisms like nonces in WordPress forms. Monitor plugin settings for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart