LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4283 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: March 24, 2026

WP DSGVO Tools (GDPR) - Broken Access Control

Published: March 24, 2026Updated: March 24, 2026Remote Exploitable

Overview

WP DSGVO Tools (GDPR) WordPress plugin <= 3.1.38 contains an unauthorized account destruction vulnerability caused by the 'super-unsubscribe' AJAX action accepting 'process_now' parameter from unauthenticated users, letting attackers permanently anonymize non-admin user accounts, exploit requires access to nonce from pages with [unsubscribe_form] shortcode.

Severity & Score

Severity: Critical
CVSS Score: 9.1
EPSS Score: 10.3%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can permanently destroy non-administrator user accounts, causing irreversible data loss and user disruption.

Mitigation

Update to a version later than 3.1.38 or the latest available version.

Social Media Activity(2 posts)

Offensive Sequence
Offensive Sequence
@offseq
Mar 25, 2026

🚨 CRITICAL: CVE-2026-4283 in WP DSGVO Tools (GDPR) plugin allows unauthenticated attackers to irreversibly destroy non-admin accounts via 'super-unsubscribe' AJAX. All versions ≤3.1.38 affected. Remove '[unsubscribe_form]' & monitor for abuse. https://radar.offseq.com/threat/cve-2026-4283-cwe-862-missing-authorization-in-leg-b0b3a8d9 #OffSeq #WordPress #Infosec

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 24, 2026

šŸ”“ CVE-2026-4283 - Critical (9.1) The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthentica... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4283/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-4283
Severity
Critical
CVSS Score
9.1
Type
broken_access_control
Status
unconfirmed
EPSS
10.3%
Social Posts
2

CWE

  • CWE-862

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Score

10.3%Probability of exploitation in the next 30 days