AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-14816

MEDIUM · CVSS 6.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The GDPR Framework By Data443 WordPress plugin versions prior to 2.4.0 is vulnerable due to inadequate verification of user authorization and identity, enabling unauthenticated attackers to manipulate consent records and inundate the site's privacy-request queue with fake entries. This could lead to data privacy compliance issues and potential reputational damage. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14816
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%
WordPress

Original NVD Description

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.