


Perceptive Security
SOC/SIEM Consultancy

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to th…
Published:
23 March 2026 at 23:00:00
Alert date:
24 March 2026 at 09:16:39
Source:
nvd.nist.gov
Web Technologies
The WP DSGVO Tools (GDPR) plugin for WordPress contains a critical vulnerability in versions up to 3.1.38 that allows unauthorized account destruction. The vulnerability exists in the 'super-unsubscribe' AJAX action which accepts a 'process_now' parameter from unauthenticated users, bypassing email confirmation flows. Attackers can permanently destroy non-administrator user accounts by submitting victim email addresses with 'process_now=1'. The attack results in randomized passwords, overwritten usernames/emails, stripped roles, anonymized comments, and wiped sensitive metadata. The required nonce is publicly available on pages containing the '[unsubscribe_form]' shortcode, making exploitation straightforward.
Technical details
Mitigation steps:
Affected products:
WP DSGVO Tools (GDPR) WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4283
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/includes/class-sp-dsgvo-ajax-action.php#L69
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/includes/class-sp-dsgvo-data-collecter.php#L250
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/includes/models/unsubscriber.php#L24
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/tags/3.1.38/public/shortcodes/super-unsubscribe/unsubscribe-form-action.php#L39
https://plugins.trac.wordpress.org/browser/shapepress-dsgvo/trunk/public/shortcodes/super-unsubscribe/unsubscribe-form-action.php#L39
https://plugins.trac.wordpress.org/changeset?old_path=/shapepress-dsgvo/tags/3.1.38&new_path=/shapepress-dsgvo/tags/3.1.39
https://www.wordfence.com/threat-intel/vulnerabilities/id/21389122-cb39-45d1-a889-b830d3a55603?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
