All verified exploits

CVE-2026-4283 Unauthenticated Account Destruction via GDPR Plugin Missing Authorization

Deterministic critical WordPress Added cve-verified-cve-2026-4283

Detects WordPress installs running the WP DSGVO Tools (GDPR) plugin at version 3.1.38 or earlier. The super-unsubscribe AJAX action accepts a process_now parameter from unauthenticated users, bypassing email confirmation and immediately anonymizing any non-admin account — randomizing the password, overwriting username and email, stripping roles, and anonymizing all comments. The required nonce is publicly available on any page with the unsubscribe form shortcode. Update WP DSGVO Tools to 3.1.39 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-4283?

Scan your domain free