Executive brief
The DSGVO All in one for WP plugin for WordPress, which helps websites manage GDPR compliance and privacy policies, contains a security flaw that allows low-level users to reset plugin settings. An attacker with a basic account on the site could revert customized privacy notices, cookie consents, and tracking policies (like Google Analytics or Facebook) back to their default values. This could lead to compliance issues or the disruption of privacy-related features on the website.
Technical details
The DSGVO All in one for WP plugin for WordPress is vulnerable to missing authorization and missing nonce verification in the dsgvo_reset_policy_service_func() function. This function fails to implement capability checks or CSRF protection when processing requests to reset plugin options. As a result, an authenticated attacker with Subscriber-level permissions or higher can trigger the function to reset all customized privacy policy content, including cookie notices and third-party tracking policies (Google Analytics, Facebook, YouTube), to their default state. The vulnerability is present in all versions up to and including 4.9.
Affected products
- mlfactory DSGVO All in one for WP up to and including 4.9
Timeline
- 2026-07-09: advisory: NVD published the CVE record.
References
- https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/tags/4.9/dsgvo_all_in_one_wp.php
- https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/tags/4.9/dsgvo_all_in_one_wp.php
- https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/trunk/dsgvo_all_in_one_wp.php
- https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/trunk/dsgvo_all_in_one_wp.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3503821%40dsgvo-all-in-one-for-wp&new=3503821%40dsgvo-all-in-one-for-wp
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6d8a5268-03a2-48c6-9c59-840a11e7a34f?source=cve