CVE-2026-14816
6.5 MEDIUMPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to forge cookie-consent records and flood privacy-request queues, potentially leading to data misuse.
- Exploitability
- Exploitation requires knowledge of the plugin version and email addresses but is relatively straightforward once those are known.
- Blast radius
- If exploited, it could lead to unauthorized access to recorded consent choices and overwhelming the site’s privacy request handling capacity.
- Prioritized remediation
- Update to the latest version of the GDPR Framework By Data443 WordPress plugin (2.4.0 or higher).
auth-bypasswebprivacy
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Weaknesses
CWE-284
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.