CVE-2026-4283Disclosure

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (8 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated attackers to permanently destroy any non-administrator user account (password randomized, username/email overwritten, roles stripped, comments anonymized, sensitive usermeta wiped) by submitting the victim's email address with `process_now=1`. The nonce required for the request is publicly available on any page containing the `[unsubscribe_form]` shortcode.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • 8 total mentions across 1 day

Deep dive

Activity timeline8 mentions / 1d
02468Mentions · 2026-03-24: 8PoC Mentioned / Linked · 2026-03-24: 1Active Exploitation · 2026-03-24: 1Patch / Workaround · 2026-03-24: 3Technical Details · 2026-03-24: 803-24
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets6 URLs
Full discourse8 posts
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-4283: WP DSGVO Tools plugin lets anyone delete WordPress user accounts remotely, no login needed. Attackers abuse the super-unsubscribe endpoint to wipe profiles instantly. Patch to 3.1.39 now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-4283 #WordPress #infosec #AppSec

    Post summary

    CVE-2026-4283 enables unauthenticated remote deletion of WordPress user accounts via a super-unsubscribe endpoint; attackers are exploiting it, but the issue is fixed in version 3.1.39.

    01010166
    55 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4283 — CVSS 9.1/10 █████████░ The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to,... Severity: CRITICAL Patch now. #cybersecurity #CVE

    Post summary

    CVE-2026-4283 allows unauthorized account destruction in the WP DSGVO Tools (GDPR) WordPress plugin; critical severity with a patch now available.

    1000023
    9 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4283 — CVSS 9.1/10 █████████░ The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/V3spP7Z2Tn

    Post summary

    The tweet highlights CVE-2026-4283, a critical flaw in the WP DSGVO Tools plugin that permits unauthorized account deletion, and urges users to apply the available patch immediately.

    1000033
    9 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4283 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super… https://www.cve.org/CVERecord?id=CVE-2026-4283

    Post summary

    A security advisory highlights that the WP DSGVO Tools plugin up to version 3.1.38 is vulnerable to unauthorized account destruction, with no PoC, exploit, or patch details provided.

    0000076
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4283 Unauthenticated Account Destruction Vulnerability in WP DSGVO Tools WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4283

    Post summary

    A newly disclosed unauthenticated account destruction vulnerability (CVE‑2026‑4283) affecting the WP DSGVO Tools WordPress plugin has been reported with basic details on VulMon.

    0000049
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4283: CRITICAL] Vulnerability in WP DSGVO Tools (GDPR) WordPress plugin (up to v3.1.38) allows unauthorized account destruction. Attackers can bypass email-confirmation flow to anonymize accounts.#cve,CVE-2026-4283,#cybersecurity https://cvefind.com/CVE-2026-4283

    Post summary

    New CVE‑2026‑4283 affecting WP DSGVO Tools (up to v3.1.38) is disclosed; it allows attackers to bypass email confirmation and delete user accounts.

    0000048
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4283 - Critical The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX a... https://www.thehackerwire.com/vulnerability/CVE-2026-4283/ https://t.co/e5JLpmlgj6

    Post summary

    A critical vulnerability (CVE-2026-4283) in the WP DSGVO Tools WordPress plugin allows unauthorized account deletion via a super-unsubscribe AJAX endpoint, with no active exploitation or patch information provided.

    0000032
    145 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4283: WP ... Publicly exposed nonce + `process_now=1` parameter = instant account nuking for any non-admin user via unauthenticated AJAX call. #WordPressSec #GDPR. https://zerodaysignal.com/vulnerability/CVE-2026-4283 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new WordPress vulnerability (CVE-2026-4283) that allows non‑admin users to delete accounts via an exposed AJAX endpoint, linking to additional details.

    0000043
    164 followersView on X

Explore more