---
id: CVE-2026-85348
title: >-
  The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF
  protection when updating one of its settings, allowing attackers to change
  that setting via a forged request granted they can trick a site administrator
  into pe…
summary: >-
  The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF
  protection when updating one of its settings, allowing attackers to change
  that setting via a forged request granted they can trick a site administrator
  into pe…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T15:17:18.367'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85348'
references:
  - url: 'https://wpscan.com/vulnerability/710ae5af-01bb-43e8-a853-df00a1ceacab/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-09T12:53:29.333Z'
---

## Overview

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
