Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters)
Vulnerability Description
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitrary victim email address and trigger immediate SAR processing via the process_now and is_ajax parameters, receiving tokenized download links (zip_link, pdf_link) in the HTTP response that expose the victim's personal data — including WordPress account details, comment author names, email addresses, IP addresses, and comment content — without any proof of ownership. The nonce used for the CSRF check is publicly rendered by the SAR shortcode form and is shared across all anonymous visitors, meaning any unauthenticated attacker can trivially obtain a valid nonce and bypass this gate entirely.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
legalweb.io WP DSGVO Tools (GDPR) 授权问题漏洞
Vulnerability Description
legalweb.io WP DSGVO Tools (GDPR)是legalweb.io个人开发者的一款用于GDPR合规的工具。 legalweb.io WP DSGVO Tools (GDPR) 3.1.39及之前版本存在授权问题漏洞,该漏洞源于授权绕过问题,可能导致未经身份验证的攻击者通过process_now和is_ajax参数触发SAR处理,获取包含受害者个人数据的tokenized下载链接。
CVSS Information
N/A
Vulnerability Type
N/A