Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-79324

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 7.5


Contact Us

Shodan ® - All rights reserved