WP GDPR Compliance < 1.4.3 - Unauthenticated Call Any Action or Update Any Option
CVE-2018-19207
Verified
Description
The WP GDPR Compliance plugin allows unauthenticated users to execute any action and update any database value. This vulnerability is due to the lack of proper validation in the Includes/Ajax.php file.
Severity
Critical
CVSS Score
9.8
Exploit Probability
88%
Affected Product
wp-gdpr-compliance
Published Date
June 16, 2025
Template Author
iamnoooob, pdresearch
CVE-2018-19207.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2018-19207
CWE ID:
cwe-425
Remediation Steps
Upgrade to WP GDPR Compliance version 1.4.3 or later, or remove the plugin if no longer needed.