CVE Explorer
CVE-2026-11869
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"WP DSGVO Tools (GDPR)","vendor":"Unknown","versions":[{"lessThan":"3.1.40","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:162f33c583adfaab2e31df399029ae2ead68dbc5f0dbc8688ff6bcc7fe25e084 · sha256:8dc8503f88e3c0fe… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:162f33c583adfaab2e31df399029ae2ead68dbc5f0dbc8688ff6bcc7fe25e084 · sha256:8dc8503f88e3c0fe… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:162f33c583adfaab2e31df399029ae2ead68dbc5f0dbc8688ff6bcc7fe25e084 · sha256:8dc8503f88e3c0fe… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/49170650-0006-4f3b-90f4-f8bb176beb7b/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:162f33c583adfaab2e31df399029ae2ead68dbc5f0dbc8688ff6bcc7fe25e084 · sha256:8dc8503f88e3c0fe… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.