CVE-2026-24539 MEDIUM

CVE-2026-24539: WordPress Protección de datos – RGPD plugin <= 0.68 - Broken Access Control vulnerability

Vendor Abcdatos
Product Protección de datos – RGPD
Weakness CWE-862 · Missing authorization
Published January 23, 2026
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in ABCdatos Protección de datos – RGPD proteccion-datos-rgpd allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protección de datos – RGPD: from n/a through <= 0.68.

Explanation of Vulnerability in Simple Terms

02Summary

ABCdatos Protección de datos – RGPD versions 0.68 and earlier contain an authorization bypass that allows unauthenticated attackers to modify data over the network. The vulnerability stems from missing access control checks on sensitive operations. No user interaction is required to exploit this flaw. Site administrators should update to a version newer than 0.68.

What an attacker can do

03Attacker Capabilities

Modify data in the application without authentication.

Potential impact on your site

04Site Impact

Unauthorized users can alter protected data, potentially compromising GDPR compliance and data integrity.

Conditions required to exploit

05Prerequisites

Network access to the vulnerable application; no authentication or user interaction required.

Key dates

06Disclosure timeline

January 23, 2026 CVE published
April 28, 2026 Record updated