DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
medium
The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This mak...
- CVSS:
- 4.3
- Affected:
- up to 4.9
- Fixed in:
- 5.0
- Disclosed:
- Jul 8, 2026
CVE-2026-4298 on NVD →
DSGVO All in one for WP [dsgvo-all-in-one-for-wp] < 4.7
unknown
[en] The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user accounts via a for...
- Affected:
- up to 4.7
- Fixed in:
- 4.7
- Disclosed:
- Feb 4, 2025
CVE-2024-13356 on NVD →
DSGVO All in one for WP <= 4.6 - Cross-Site Request Forgery to Account Deletion
medium
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user accounts via a forged r...
- CVSS:
- 6.5
- Affected:
- up to 4.6
- Fixed in:
- 4.7
- Disclosed:
- Feb 3, 2025
CVE-2024-13356 on NVD →
DSGVO All in one for WP [dsgvo-all-in-one-for-wp] < 4.6
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This issue affects DSGVO All in one for WP: from n/a through 4.5.
- Affected:
- up to 4.6
- Fixed in:
- 4.6
- Disclosed:
- Aug 29, 2024
CVE-2024-43964 on NVD →
DSGVO All in one for WP <= 4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 4.5
- Fixed in:
- 4.6
- Disclosed:
- Aug 26, 2024
CVE-2024-43964 on NVD →
DSGVO All in one for WP [dsgvo-all-in-one-for-wp] < 4.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3.
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 21, 2024
CVE-2024-27967 on NVD →
DSGVO All in one for WP <= 4.3 - Cross-Site Request Forgery
medium
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3. This is due to missing or incorrect nonce validation on the dsgvo_ajax_remove_usr_ip() function. This makes it possible for unauthenticated attackers to remove IP addresses via a forged re...
- CVSS:
- 4.3
- Affected:
- up to 4.3
- Fixed in:
- 4.4
- Disclosed:
- Mar 13, 2024
CVE-2024-27967 on NVD →
DSGVO All in one for WP [dsgvo-all-in-one-for-wp] < 4.3
unknown
[en] The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.3
- Fixed in:
- 4.3
- Disclosed:
- Oct 3, 2022
CVE-2022-2628 on NVD →
DSGVO All in one for WP <= 4.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dsdvo_customimprinttext’ parameter in versions up to, and including, 4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permission...
- CVSS:
- 5.5
- Affected:
- up to 4.2
- Fixed in:
- 4.3
- Disclosed:
- Sep 12, 2022
CVE-2022-2628 on NVD →
DSGVO All in one for WP [dsgvo-all-in-one-for-wp] < 4.0
unknown
[en] The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to...
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- May 24, 2021
CVE-2021-24294 on NVD →
DSGVO All in one for WP <= 3.9 - Unauthenticated Stored Cross-Site Scripting
medium
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to gain...
- CVSS:
- 6.1
- Affected:
- up to 3.9
- Fixed in:
- 4.0
- Disclosed:
- May 7, 2021
CVE-2021-24294 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database