Plugin Vulnerability Hub
Plugin 6 known issues Latest disclosed Mar 23, 2026

WP DSGVO Tools (GDPR) Vulnerabilities

Review known vulnerability records for the WordPress plugin WP DSGVO Tools (GDPR) (`shapepress-dsgvo`), including severity, CVE references, affected versions, and patch status.

Known Records
6
High or Critical
3
Linked CVEs
6
Last Updated
Mar 23, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WP DSGVO Tools (GDPR) so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
6 records include a published patch path.
Severity Mix
1 critical and 2 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for WP DSGVO Tools (GDPR)

Sorted by latest disclosure date so newly published issues surface first.

Plugin Critical Patched: Yes CVE-2026-4283
WP DSGVO Tools (GDPR) <= 3.1.38 - Missing Authorization to Unauthenticated Account Destruction of Non-Admin Users

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the int...

Published
Mar 23, 2026
Patched Release
3.1.39
Affected Versions
Versions up to 3.1.38
Next Step
Update to 3.1.39 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0914
WP DSGVO Tools (GDPR) <= 3.1.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lw_content_block' Shortcode

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content_block' shortcode in all versions up to, and including, 3.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

Published
Jan 22, 2026
Patched Release
3.1.37
Affected Versions
Versions up to 3.1.36
Next Step
Update to 3.1.37 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3201
WP DSGVO Tools (GDPR) <= 3.1.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' shortcode in all versions up to, and including, 3.1.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...

Published
May 22, 2024
Patched Release
3.1.33
Affected Versions
Versions up to 3.1.32
Next Step
Update to 3.1.33 or newer if supported.
Plugin High Patched: Yes CVE-2021-4358
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Stored Cross-Site Scripting

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Published
Sep 24, 2021
Patched Release
3.1.24
Affected Versions
Versions before 3.1.24
Next Step
Update to 3.1.24 or newer if supported.
Plugin High Patched: Yes CVE-2021-42359
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Arbitrary Post Deletion

WP DSGVO Tools (GDPR)

Published
Sep 21, 2021
Patched Release
3.1.24
Affected Versions
Versions up to 3.1.23
Next Step
Update to 3.1.24 or newer if supported.
Plugin Medium Patched: Yes CVE-2019-15777
WP DSGVO Tools (GDPR) <= 2.2.18 - Cross-Site Scripting

The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.

Published
Aug 27, 2019
Patched Release
2.2.19
Affected Versions
Versions before 2.2.19
Next Step
Update to 2.2.19 or newer if supported.