CVE-2026-39797: WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
Affected Software
1 affected component
Data443 GDPR Framework By Data443<=2.5.0
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior access to target a vulnerable site.
2
Which installations are affected?
Data443 GDPR Framework By Data443 versions 2.5.0 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration is required.
3
What impact could successful exploitation have?
The assigned critical severity vector indicates potential for high confidentiality, integrity, and availability impact, with network-based exploitation requiring low attack complexity and no user interaction.