In this GDPR plugin hack, the attacker gets access to create an option in the database which in turn gives him access to the admin panel. Once he has access, he can perform various malicious actions.
Some things you should check:
– if a new admin user is added
– if your site url is changed
– if the website gets redirected
To read more about this issue and possibles fixes, you can refer to the following link:
https://www.getastra.com/blog/cms/wordpress-security/wordpress-gdpr-plugin-exploit-privilege-escalation-vulnerability/