CVE-2026-85348: GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF

Published Oct 9, 2026
·
Updated

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Affected Software

1 affected component
WordPress GDPR Data Request Form>=1.5<=1.7.1

Event History

Oct 9, 2026
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can be targeted by this issue?

Sites using the WordPress GDPR Data Request Form plugin through version 1.7.1 are affected. Exploitation targets a site administrator, because the attacker must cause that administrator to perform an action such as clicking a forged link.

2

What can an attacker change?

An attacker can update one of the plugin's settings: the DPO email address. The available information does not indicate that the attacker needs authentication, but successful exploitation requires administrator interaction.

3

How urgent is remediation if patching is delayed?

Until the plugin is updated beyond the affected versions, reduce the chance that administrators follow untrusted links or submit untrusted pages while logged in. The stated impact is unauthorized modification of the setting rather than disclosure or service disruption.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203