WordPress WP DSGVO Tools是WordPress基金会开源的一个GDPR合规工具插件。 WordPress WP DSGVO Tools 3.1.40之前版本存在授权问题漏洞,该漏洞源于未对数据主体访问请求功能的即时处理路径进行授权检查,可能导致未经身份验证的攻击者通过提供用户邮箱生成并下载完整的个人数据导出,包括姓名、邮寄地址、电话号码、邮箱和评论内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP DSGVO Tools (GDPR) | < 3.1.40 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP DSGVO Tools (GDPR) | 0 ~ 3.1.40 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12516 | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy | |
| CVE-2026-12517 | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint | |
| CVE-2026-12270 | Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endp | |
| CVE-2026-11571 | Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Ar | |
| CVE-2026-11875 | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access |
No comments yet