CVE-2018-19207

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
12/11/2018
Last modified:
03/10/2019

Description

The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:van-ons:wp-gdpr-compliance:*:*:*:*:*:wordpress:*:* 1.4.3 (excluding)