CVE-2026-79324 | Mageplaza GDPR for Magento up to 4.2.9 Address Delete Controller id ID missing authentication
A vulnerability classified as critical was found in Mageplaza GDPR for Magento up to 4.2.9. This issue affects some unknown processing of the file /customer/address/delete/id of the component Address Delete Controller. The manipulation of the argument ID results in missing authentication.
This vulnerability is identified as CVE-2026-79324. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More