


Perceptive Security
SOC/SIEM Consultancy

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to th…
Published:
23 March 2026 at 23:00:00
Alert date:
24 March 2026 at 16:16:53
Source:
nvd.nist.gov
Web Technologies
The WP DSGVO Tools (GDPR) plugin for WordPress contains a critical vulnerability allowing unauthorized account destruction. Unauthenticated attackers can permanently destroy non-administrator user accounts by exploiting the super-unsubscribe AJAX action with a process_now parameter. The vulnerability affects all versions up to and including 3.1.38. Attackers can submit a victim's email address with process_now=1 to trigger irreversible account anonymization, including password randomization, username/email overwriting, role stripping, comment anonymization, and sensitive metadata wiping. The required nonce is publicly available on pages containing the unsubscribe_form shortcode, making exploitation straightforward for attackers.
Technical details
Mitigation steps:
Affected products:
WP DSGVO Tools (GDPR) WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4283
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/includes/class-sp-dsgvo-ajax-action.php#L69
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/includes/class-sp-dsgvo-data-collecter.php#L250
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/includes/models/unsubscriber.php#L24
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/public/shortcodes/super-unsubscribe/unsubscribe-form-action.php#L39
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/trunk/public/shortcodes/super-unsubscribe/unsubscribe-form-action.php#L39
https://plugins.trac.wordpress.org/changeset?old_path=/shapepress-dsgvo/tags/3.1.38&new_path=/shapepress-dsgvo/tags/3.1.39
https://www.wordfence.com/threat-intel/vulnerabilities/id/21389122-cb39-45d1-a889-b830d3a55603?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
