MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #11

WordPress GDPR Data Request Form plugin flaw disclosed as EUVD-2026-95706

Original: 🚨 EUVD-2026-95706 πŸ“Š Score: 4.3/10 (CVSS v3.1) πŸ“¦ Product: GDPR Data Request Form 🏒 Vendor: Unknown πŸ“… Updated: 2026-10-09

A moderate-severity vulnerability, EUVD-2026-95706, has been catalogued in the GDPR Data Request Form WordPress plugin through version 1.7.1. The plugin lacks CSRF protection when updating one of its settings, meaning an attacker could trick a logged-in administrator into unknowingly changing that setting. The flaw carries a CVSS v3.1 score of 4.3 out of 10, and the vendor is listed as unknown. The advisory was updated on 9 October 2026, and administrators running the plugin are advised to check for updates.

Why now: A newly published vulnerability advisory for a widely used category of WordPress plugin prompts site administrators to check whether they are affected.

GDPR Data Request FormWordPressEUVD

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1606632