Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #11
WordPress GDPR Data Request Form plugin flaw disclosed as EUVD-2026-95706
Original: π¨ EUVD-2026-95706 π Score: 4.3/10 (CVSS v3.1) π¦ Product: GDPR Data Request Form π’ Vendor: Unknown π Updated: 2026-10-09
A moderate-severity vulnerability, EUVD-2026-95706, has been catalogued in the GDPR Data Request Form WordPress plugin through version 1.7.1. The plugin lacks CSRF protection when updating one of its settings, meaning an attacker could trick a logged-in administrator into unknowingly changing that setting. The flaw carries a CVSS v3.1 score of 4.3 out of 10, and the vendor is listed as unknown. The advisory was updated on 9 October 2026, and administrators running the plugin are advised to check for updates.
Why now: A newly published vulnerability advisory for a widely used category of WordPress plugin prompts site administrators to check whether they are affected.
GDPR Data Request FormWordPressEUVD
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1606632