Extension WordPress

Vulnérabilités DSGVO All in one for WP

Cette page rassemble les failles publiées pour DSGVO All in one for WP, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de DSGVO All in one for WP

6 fiches

CVE-2026-4298 Moyenne · 4,3
DSGVO All in one for WP

DSGVO All in one for WP <= 4.9 – Missing Authorization to Authenticated (Subscriber+) Settings Reset

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while…

Versions affectées

*-4.9

Correctif

5.0

Publication

08/07/2026

CVE-2021-24294 Moyenne · 6,1
DSGVO All in one for WP

DSGVO All in one for WP <= 3.9 – Unauthenticated Stored Cross-Site Scripting

The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This…

Versions affectées

*-3.9

Correctif

4.0

Publication

07/05/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités