Vulnerability record · CVE-2018-19207 · published 12 November 2018
CVE-2018-19207: WP GDPR Compliance plugin allows unauthenticated remote code execution
VVan Ons · Wp Gdpr Compliance
The Van Ons WP GDPR Compliance plugin before 1.4.3 for WordPress mishandles input passed to $wpdb->prepare(), allowing remote attackers to execute arbitrary code. The flaw was exploited in the wild in November 2018, and the plugin is widely deployed on WordPress sites handling GDPR consent flows.
Description
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, confirmed in-the-wild exploitation, and an EPSS score near 0.88 make this an urgent patch.
What it is
The Van Ons WP GDPR Compliance plugin before 1.4.3 for WordPress mishandles input passed to $wpdb->prepare(), allowing remote attackers to execute arbitrary code. The flaw was exploited in the wild in November 2018, and the plugin is widely deployed on WordPress sites handling GDPR consent flows.
Impact
An unauthenticated attacker can run arbitrary code on the affected WordPress host, leading to full site compromise, data theft, or use of the server as a foothold.
Attack surface
Reachable over the network through the plugin's WordPress endpoints; the CVSS vector shows no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N).
Exploitation
Exploited in the wild in November 2018 per the description, and reference tags include Exploit; the CVE is not in CISA KEV, but EPSS is 0.88 (99.8th percentile), indicating very high likelihood of exploitation activity.
What to do
- Update the WP GDPR Compliance plugin to version 1.4.3 or later immediately.
- If patching is not possible, deactivate and remove the plugin until it can be updated.
- Audit WordPress sites for the plugin and check for signs of compromise such as unexpected admin users, modified files, or outbound connections.
- Apply WAF rules blocking exploit attempts against the plugin's endpoints.
- Rotate WordPress salts, admin credentials, and any secrets stored on affected hosts after remediation.
Detection
- Search web server logs for requests to wp-gdpr-compliance plugin paths with suspicious parameters or SQL-like payloads.
- Monitor for unexpected PHP file creation or modification in WordPress plugin, upload, and theme directories.
- Alert on new or modified WordPress administrator accounts and unexpected scheduled tasks (cron) after plugin exposure.
- Review outbound network connections from the web server for command-and-control or exfiltration patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105921 | Third Party AdvisoryVDB Entry |
| https://wordpress.org/plugins/wp-gdpr-compliance/#developers | ProductVendor Advisory |
| https://wpvulndb.com/vulnerabilities/9144 | ExploitThird Party Advisory |
| https://www.wordfence.com/blog/2018/11/trends-following-vulnerability-in-wp-gdpr-compliance-plugin/ | ExploitThird Party Advisory |
| http://www.securityfocus.com/bid/105921 | Third Party AdvisoryVDB Entry |
| https://wordpress.org/plugins/wp-gdpr-compliance/#developers | ProductVendor Advisory |
| https://wpvulndb.com/vulnerabilities/9144 | ExploitThird Party Advisory |
| https://www.wordfence.com/blog/2018/11/trends-following-vulnerability-in-wp-gdpr-compliance-plugin/ | ExploitThird Party Advisory |
Track CVE-2018-19207 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19207), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.