Executive brief
Complianz is a popular WordPress plugin used to manage GDPR and privacy compliance. A security vulnerability in versions 7.5.0 and earlier allows an administrative user to inject malicious code into the website's server. If exploited, this could lead to full site takeover, data theft, or the disruption of website services, though it requires high-level administrative access to perform.
Technical details
The Complianz plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 7.5.0. This issue stems from the deserialization of untrusted data (CWE-502) provided by a user with administrative privileges. An attacker with high-level access can exploit this by submitting specially crafted input that, when processed by the server, triggers the execution of arbitrary PHP code or other malicious actions if a suitable Property-Oriented Programming (POP) chain is present in the environment. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from the developer.
Affected products
- Complianz Complianz <= 7.5.0
Timeline
- 2026-06-24: other: Vulnerability reported by researcher to Patchstack
- 2026-07-22: advisory: Initial advisory published by Patchstack
- 2026-07-23: disclosed: CVE published to NVD