Junglewise Threat Intelligence

CVE-2026-79324: Mageplaza GDPR for Magento 2 missing authorization in address delete

CVE-2026-79324 · Severity: high · CVSS 7.5 · Published 2026-09-09

Executive brief

Mageplaza GDPR is a Magento 2 extension designed to help e-commerce stores comply with GDPR data protection regulations. A critical flaw allows unauthenticated attackers to delete any customer's saved addresses—including billing and shipping information—by simply sending a single web request, without requiring login or any special permissions. An attacker could systematically erase all customer addresses from a store, causing data loss and disrupting the checkout experience for all affected customers.

Technical details

The vulnerability is a missing authorization check (CWE-862 / CWE-639 IDOR) in the Address Delete controller. The controller extends the legacy Magento\Framework\App\Action\Action class instead of AbstractAccount, which bypasses the built-in customer login plugin. The execute() method reads an address ID from the request and calls deleteById() with no authentication check, no ownership verification (comparing target address customer ID to session customer ID), and no form key validation. An attacker can delete any address by crafting a simple GET request to /customer/address/delete/id/{id}; iterating numeric IDs erases all saved addresses in the store. No fix is yet available (module version through 4.2.9 is affected; version 4.3.0 released 2026-08-21 version history does not indicate a patch).

Affected products

  • Mageplaza GDPR for Magento 2 through 4.2.9

Timeline

  • 2026-09-09: disclosed

References