DSGVO for WP is a WordPress plugin that provides data-protection and privacy-compliance functionality for site administrators handling European regulatory requirements. The plugin's vulnerability profile remains narrow and focused on its core compliance and data-handling role; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dsgvo For Wp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27967HIGH Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3. | Apr 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-13356MEDIUM The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce va | Feb 4, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-43964MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This issue a | Aug 29, 2024 | 5.4 | 17 | NO | NO |
CVE-2022-2628MEDIUM The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr | Oct 3, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dsgvo For Wp.
Media articles that mention a CVE ID that affects a product developed by Dsgvo For Wp — matched by CVE ID, not by vendor name.