/Vulnerability Library

WP GDPR Compliance < 1.4.3 - Unauthenticated Call Any Action or Update Any Option

CVE-2018-19207
Verified

Description

The WP GDPR Compliance plugin allows unauthenticated users to execute any action and update any database value. This vulnerability is due to the lack of proper validation in the Includes/Ajax.php file.

Severity

Critical

CVSS Score

9.8

Exploit Probability

88%

Affected Product

wp-gdpr-compliance

Published Date

June 16, 2025

Template Author

iamnoooob, pdresearch

CVE-2018-19207.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2018-19207
CWE ID:
cwe-425

References

https://wpvulndb.com/vulnerabilities/9157https://github.com/aeroot/WP-GDPR-Compliance-Plugin-Exploit

Remediation Steps

Upgrade to WP GDPR Compliance version 1.4.3 or later, or remove the plugin if no longer needed.