Medium severity6.5NVD Advisory· Published Nov 19, 2024· Updated Jun 17, 2026
CVE-2024-11069
CVE-2024-11069
Description
The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to delete arbitrary users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- welaunch/WordPress GDPRv5Range: 0
- Range: <=2.0.2
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/a089026a-5da9-467c-a1e4-622bb74363e2nvdThird Party Advisory
- www.welaunch.io/en/product/wordpress-gdpr/nvdProduct
News mentions
0No linked articles in our index yet.