{"id":"CVE-2026-14816","published":"2026-08-04T07:16:28.600","lastModified":"2026-08-04T15:16:25.427","description":"The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/72af92a2-afe6-4e5a-9a1a-6f6e97bbcd85/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to forge cookie-consent records and flood privacy-request queues, potentially leading to data misuse.","exploitability":"Exploitation requires knowledge of the plugin version and email addresses but is relatively straightforward once those are known.","blast_radius":"If exploited, it could lead to unauthorized access to recorded consent choices and overwhelming the site’s privacy request handling capacity.","remediation":"Update to the latest version of the GDPR Framework By Data443 WordPress plugin (2.4.0 or higher).","tags":["auth-bypass","web","privacy"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:05:06.539Z"}}