Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
ssvc
|
Fri, 09 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-09T15:00:19.278Z
Reserved: 2026-09-03T17:17:14.415Z
Link: CVE-2026-85348
Updated: 2026-10-09T14:50:30.347Z
Status : Deferred
Published: 2026-10-09T12:17:12.500
Modified: 2026-10-09T15:17:18.367
Link: CVE-2026-85348
No data.
OpenCVE Enrichment
Updated: 2026-10-09T13:00:08Z
-
CWE-352
Cross-Site Request Forgery (CSRF)