CVE-2026-14816: CWE-284 Improper Access Control in The GDPR Framework By Data443
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.
AI Analysis
Technical Summary
CVE-2026-14816 is an improper access control vulnerability (CWE-284) in The GDPR Framework By Data443 WordPress plugin prior to version 2.4.0. The plugin fails to verify the authorization or identity of users submitting cookie-consent choices and privacy requests. This allows unauthenticated attackers to create forged consent records for any email address and to overwhelm the site's privacy-request queue with arbitrary entries, potentially disrupting privacy request handling.
Potential Impact
Unauthenticated attackers can forge consent records for arbitrary email addresses, potentially undermining the integrity of consent data. Additionally, attackers can flood the privacy-request queue with arbitrary entries, which may disrupt or degrade the site's ability to process legitimate privacy requests effectively.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor for updates from Data443 regarding a patch or mitigation steps. Avoid relying on the plugin for critical consent verification without additional controls.
CVE-2026-14816: CWE-284 Improper Access Control in The GDPR Framework By Data443
Description
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14816 is an improper access control vulnerability (CWE-284) in The GDPR Framework By Data443 WordPress plugin prior to version 2.4.0. The plugin fails to verify the authorization or identity of users submitting cookie-consent choices and privacy requests. This allows unauthenticated attackers to create forged consent records for any email address and to overwhelm the site's privacy-request queue with arbitrary entries, potentially disrupting privacy request handling.
Potential Impact
Unauthenticated attackers can forge consent records for arbitrary email addresses, potentially undermining the integrity of consent data. Additionally, attackers can flood the privacy-request queue with arbitrary entries, which may disrupt or degrade the site's ability to process legitimate privacy requests effectively.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor for updates from Data443 regarding a patch or mitigation steps. Avoid relying on the plugin for critical consent verification without additional controls.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-06T08:13:11.116Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7187cebf32cb7a34e19ab1
Added to database: 08/04/2026, 06:33:50 UTC
Last enriched: 08/04/2026, 07:09:18 UTC
Last updated: 08/04/2026, 12:56:01 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.