search
GDPR Data Request Form
Trends
- 1WordPress GDPR Data Request Form plugin flaw disclosed as EUVD-2026-95706โ๐จ EUVD-2026-95706 ๐ Score: 4.3/10 (CVSS v3.1) ๐ฆ Product: GDPR Data Request Form ๐ข Vendor: Unknown ๐ Updated: 2026-10-09
A moderate-severity vulnerability, EUVD-2026-95706, has been catalogued in the GDPR Data Request Form WordPress plugin through version 1.7.1. The plugin lacks CSRF protection when updating one of its settings, meaning an attacker could trick a logged-in administrator into unknowingly changing that setting. The flaw carries a CVSS v3.1 score of 4.3 out of 10, and the vendor is listed as unknown. The advisory was updated on 9 October 2026, and administrators running the plugin are advised to check for updates.