CVE-2018-19207 affects the Van Ons WP GDPR Compliance (wp-gdpr-compliance) WordPress plugin before version 1.4.3. The vulnerability is caused by improper handling of input passed to $wpdb->prepare(), resulting in a SQL injection condition. According to the provided content, this flaw can be leveraged by remote attackers to achieve arbitrary code execution. The issue was reportedly exploited in the wild in November 2018.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python proof-of-concept exploit for CVE-2018-19207 affecting the WordPress WP GDPR Compliance plugin. It contains only two files: a minimal README naming the CVE and a single executable Python script, wp_gdpr_compliance.py. The script is lightly obfuscated by embedding its real logic as a base64-encoded string and executing the decoded code at runtime. Functionally, the exploit performs an unauthenticated web attack against supplied WordPress targets. For each target listed in an input file, it normalizes the URL by prepending http:// if needed, fetches the site homepage, extracts an ajaxSecurity token from the page content using a regex, and then sends a POST request to /wp-admin/admin-ajax.php. The POST body invokes action wpgdprc_process_action with JSON data instructing the vulnerable plugin to save the setting new_admin_email to an attacker-controlled email address. If the response matches the expected success pattern, the script marks the site as vulnerable and logs it locally. The exploit's main capability is admin takeover facilitation rather than direct shell execution. By changing the admin email address, the attacker can request a password reset and receive the reset link at the supplied email account. The script explicitly logs successful targets as '<site>/wp-login.php --> reset link sent to: <email>', confirming its intended post-exploitation path. Repository structure is minimal and purpose-built for bulk exploitation: one input list of targets is expected at runtime, one function handles exploitation, one function saves results, and the main routine iterates over all targets. No framework is used, no advanced payload customization exists, and there is no persistence or remote code execution payload included.
This repository contains a single Metasploit auxiliary module targeting a privilege escalation vulnerability (CVE-2018-19207) in the WordPress WP GDPR Compliance plugin (versions <= 1.4.2). The exploit abuses the lack of capability checks in the plugin's AJAX handler to set arbitrary WordPress options, enabling user registration and setting the default role to administrator. It then registers a new user with attacker-supplied credentials, effectively granting admin access. The module optionally allows changing the admin email address. The attack is performed over HTTP(S) by sending crafted POST requests to the /wp-admin/admin-ajax.php endpoint. The code is written in Ruby and is structured as a standard Metasploit module, with options for specifying the new user's email and username. The exploit does not provide a shell directly but suggests using another Metasploit module for shell access after successful exploitation.
This repository contains a Python 2.7 exploit script targeting CVE-2018-19207, a vulnerability in the WP GDPR Compliance plugin for WordPress (versions <=1.4.2). The exploit leverages insecure AJAX actions to enable user registration, set the default role to administrator, register a new user with attacker-supplied credentials, and then revert the settings to their original state. The script requires the attacker to specify the target site URL, desired username, and a valid email address (to receive the password setup link). The main code file is 'wp_gdpr_compliance_exploit.py', which uses the 'requests' library to interact with the target WordPress instance. The README provides usage instructions and requirements. The exploit is operational and can result in full administrative access to vulnerable WordPress sites.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.