CVE-2026-85348 - GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF
CVE ID :CVE-2026-85348
Published : Oct. 9, 2026, 11:03 a.m. | 43 minutes ago
Description :The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 9, 2026, 11:03 a.m. | 43 minutes ago
Description :The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...