WP GDPR Plugin - critical WordPress vulnerability (security flaw)
Hello Visitor,
currently, a vulnerability rated as very critical has been discovered in the WP GDPR Compliance plugin (100,000+ active installations).
This allows attackers to wp_options table. In the current wave of attacks, the default user role is being changed to Administrator set, and user registration enabled, so that the site can then be further manipulated with a newly created admin account.
In version 1.4.3, the security flaw was fixed.
More info in the blog:
https://website-bereinigung.de/blog/wp-gdpr-compliance-sicherheitsluecke

currently, a vulnerability rated as very critical has been discovered in the WP GDPR Compliance plugin (100,000+ active installations).
This allows attackers to wp_options table. In the current wave of attacks, the default user role is being changed to Administrator set, and user registration enabled, so that the site can then be further manipulated with a newly created admin account.
In version 1.4.3, the security flaw was fixed.
More info in the blog:
https://website-bereinigung.de/blog/wp-gdpr-compliance-sicherheitsluecke
