CVE-2026-85348: GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF
The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
Who can be targeted by this issue?
Sites using the WordPress GDPR Data Request Form plugin through version 1.7.1 are affected. Exploitation targets a site administrator, because the attacker must cause that administrator to perform an action such as clicking a forged link.
What can an attacker change?
An attacker can update one of the plugin's settings: the DPO email address. The available information does not indicate that the attacker needs authentication, but successful exploitation requires administrator interaction.
How urgent is remediation if patching is delayed?
Until the plugin is updated beyond the affected versions, reduce the chance that administrators follow untrusted links or submit untrusted pages while logged in. The stated impact is unauthorized modification of the setting rather than disclosure or service disruption.