DSGVO All in one for WP
cpe:2.3:a:dsgvo-for-wp:dsgvo_all_in_one_for_wp:*:*:*:*:wordpress:*:*
- <= 4.6
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DSGVO All in One for WP WordPress plugin, affecting all versions through 4.6. The issue arises from inadequate nonce validation in the user_remove_form.php file, enabling unauthenticated attackers to delete admin user accounts by tricking an administrator into clicking a link.
Exploitation of this vulnerability allows for the unauthorized deletion of admin user accounts.
To reproduce this vulnerability, an attacker must send a forged request to a WordPress site using the DSGVO All in One for WP plugin version 4.6 or earlier. The request must include a valid nonce for the 'once_remove_user' action. This can be achieved by convincing an administrator to click a link that triggers the request, such as through a phishing email or message.
Users are advised to update the DSGVO All in One for WP WordPress plugin to version 4.7 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.