Vulnerabilities / Groundhogg / WPSEC-2026-0770
Groundhogg <= 4.9.2 - Unauthenticated Insecure Direct Object Reference to Unsent and Private Broadcast Disclosure via Campaign Archive
Medium 5.3
CWE-639Fixed in 4.9.3
- ID
- WPSEC-2026-0770
- Plugin
- Groundhogg — CRM, Newsletters, and Marketing Automation (groundhogg)
- Affected
- all versions before 4.9.3
- Remediation
- Update to 4.9.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-11
- Attack surface
- Groundhogg on WPSec AttackSurface
- Fix released
- Published
Description
The Groundhogg plugin for WordPress is vulnerable to Insecure Direct Object Reference via the campaign archive broadcast view in all versions up to, and including, 4.9.2, due to missing validation that the requested broadcast ID is a sent email broadcast belonging to the campaign in the URL. This makes it possible for unauthenticated attackers to enumerate sequential broadcast IDs under any public campaign's archive URL and read the contents of any email broadcast on the site, including unsent broadcasts and broadcasts belonging to campaigns that are not public.
References
- https://wpsec.com/vuln/WPSEC-2026-0770/
- https://plugins.svn.wordpress.org/groundhogg/tags/4.9.3/
- https://wordpress.org/plugins/groundhogg/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS