DSGVO All in One for WP WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Account Deletion

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DSGVO All in One for WP WordPress plugin, affecting all versions through 4.6. The issue arises from inadequate nonce validation in the user_remove_form.php file, enabling unauthenticated attackers to delete admin user accounts by tricking an administrator into clicking a link.

Impact

Exploitation of this vulnerability allows for the unauthorized deletion of admin user accounts.

Reproduction

To reproduce this vulnerability, an attacker must send a forged request to a WordPress site using the DSGVO All in One for WP plugin version 4.6 or earlier. The request must include a valid nonce for the 'once_remove_user' action. This can be achieved by convincing an administrator to click a link that triggers the request, such as through a phishing email or message.

Remediation

Users are advised to update the DSGVO All in One for WP WordPress plugin to version 4.7 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
7.6
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.