The WP GDPR Compliance plugin allows unauthenticated users to execute any action and update any database value. This vulnerability is due to the lack of proper validation in the Includes/Ajax.php file.
id: CVE-2018-19207
info:
name: WP GDPR Compliance < 1.4.3 - Unauthenticated Call Any Action or Up
...