WP DSGVO Tools (GDPR) WordPress Plugin Unauthenticated Personal Data Export Vulnerability

Vulnerability

A vulnerability exists in the WP DSGVO Tools (GDPR) WordPress plugin in versions prior to 3.1.40. The plugin's data subject access request feature lacks proper authorization checks, enabling unauthenticated attackers to generate and download personal data exports of any user, customer, or commenter by simply providing their email address. The exported data includes the individual's name, postal address, phone number, email, and comment content.

Impact

Exploitation of this vulnerability allows for unauthorized access to and download of personal data, including names, addresses, phone numbers, emails, and comment content, of any WordPress user, customer, or commenter.

Reproduction

To reproduce this vulnerability, first ensure that a published Subject Access Request (SAR) form page exists. This can be done by using the plugin's setup feature or manually creating and publishing a page with the appropriate shortcode. Next, as an unauthenticated user, access the SAR form page and copy the hidden nonce value. Then, send a request to the WordPress site's admin-ajax.php file, using the 'subject-access-request' action. Include the copied nonce, the email address of the target user, and other required form data. The response will contain a token that can be used to download the personal data export. Finally, use the token to request the data export, which will be delivered as a PDF containing the victim's personal information.

Remediation

Users are advised to update the WP DSGVO Tools (GDPR) WordPress plugin to version 3.1.40 or later.

Added: Jul 9, 2026, 7:30 AM
Updated: Jul 9, 2026, 7:30 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
9.3
remediation
7.7
relevance
9.2
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.