CVE-2026-14816
MEDIUM NVDCVSS Score
6.5
Severity
MEDIUM
Source
NVD
Published
Aug 04, 2026
Description
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.