What is CVE-2026-14816?
CVE-2026-14816: The 'GDPR Framework By Data443' WordPress plugin before version 2.4.0 improperly verifies authorization and data subject identity when recording cookie-consent choices and privacy requests. This allows unauthenticated attackers to forge consent records for arbitrary email addresses. Sites using the plugin should immediately update to version 2.4.0 or later.
Azərbaycanca: CVE-2026-14816: Data443 şirkətinin 'GDPR Framework' WordPress plaginində (2.4.0 versiyasından əvvəl) autentifikasiya və şəxsin təsdiqi zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmamış hücumçulara ixtiyari e-poçt ünvanları üçün saxta razılıq qeydləri yaratmağa imkan verir. Plagindən istifadə edən saytlar dərhal 2.4.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What type of attack can be performed using the CVE-2026-14816 vulnerability?
The CVE-2026-14816 vulnerability allows unauthenticated attackers to forge consent records for arbitrary email addresses.
To which version should the 'GDPR Framework By Data443' plugin be updated to mitigate CVE-2026-14816?
It is recommended to update the plugin to version 2.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.