Junglewise Threat Intelligence

CVE-2026-10034: Shapepress WP DSGVO Tools (GDPR) authorization bypass in SAR processing

CVE-2026-10034 · Severity: medium · CVSS 5.3 · Published 2026-06-19

Executive brief

The WP DSGVO Tools (GDPR) plugin for WordPress, which helps websites comply with European privacy laws, contains a security flaw in its data request system. An unauthorized person can trick the plugin into generating a data download link for any user's account by simply knowing their email address. This could lead to the exposure of sensitive personal information, including account details, IP addresses, and private comment history, without the attacker needing to prove they own the account.

Technical details

The WP DSGVO Tools (GDPR) plugin for WordPress suffers from a missing authorization check (CWE-862) in its Subject Access Request (SAR) processing logic. By supplying an arbitrary victim email address and manipulating the 'process_now' and 'is_ajax' parameters, an unauthenticated attacker can trigger immediate data processing. The plugin then returns tokenized download links (ZIP and PDF) directly in the HTTP response. Furthermore, the security nonce intended to prevent CSRF is rendered publicly via the SAR shortcode and shared among all anonymous visitors, making it trivial to bypass. This flaw allows for the unauthorized extraction of WordPress account details, comment history, email addresses, and IP addresses. The vulnerability is present in versions up to 3.1.39.

Affected products

  • Shapepress WP DSGVO Tools (GDPR) up to, and including, 3.1.39

Timeline

  • 2026-06-19: disclosed: CVE published to NVD dataset

References

Related threats