{
 "id": "WPSEC-2026-0577",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0577/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0577/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0577/index.md",
 "title": "HollerBox — Fast & Effective Popups & Lead-Generation <= 2.3.13 - Unauthenticated Insecure Direct Object Reference to Arbitrary Post Unpublishing via Popup REST Endpoints",
 "description": "The HollerBox plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0 up to, and including, 2.3.13. The public popup submission, impression and conversion REST endpoints load a popup from a user-supplied ID without checking that the post is a HollerBox popup, and loading a popup runs a legacy settings migration that saves changes to that post. This makes it possible for unauthenticated attackers to change the status of arbitrary posts, pages and other content to draft, taking them off the site, and to write HollerBox settings into their post meta. The submission endpoint also accepted submissions to unpublished popups, running their configured integrations.",
 "plugin": {
  "slug": "holler-box",
  "name": "HollerBox — Fast & Effective Popups & Lead-Generation",
  "full_name": "HollerBox — Fast & Effective Popups & Lead-Generation",
  "wordpress_org": "https://wordpress.org/plugins/holler-box/",
  "advisories_url": "https://wpsec.com/vuln/plugin/holler-box/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/holler-box"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.0",
    "from_inclusive": true,
    "to": "2.3.15",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.0 before 2.3.15"
  ]
 },
 "introduced_in": "2.0",
 "fixed_in": "2.3.15",
 "remediation": "Update to 2.3.15 or later.",
 "fix_released": "2026-10-06T16:29:18+00:00",
 "published": "2026-10-07T16:47:54+00:00",
 "updated": "2026-10-06T19:05:43.098861+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0577/",
  "https://plugins.svn.wordpress.org/holler-box/tags/2.3.15/",
  "https://wordpress.org/plugins/holler-box/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/holler-box",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}