Unauthorized Data Deletion Vulnerability in WordPress GDPR Plugin
CVE-2024-11069
9.1CRITICAL
What is CVE-2024-11069?
The WordPress GDPR Plugin is susceptible to unauthorized data deletion due to a missing capability check in the 'WordPress_GDPR_Data_Delete::check_action' function. This vulnerability allows unauthenticated attackers to delete arbitrary users from the system. Affected users should update to the latest version to mitigate the risk of unauthorized access and protect their data integrity.
Affected Version(s)
WordPress GDPR * <= 2.0.2