Vulnerabilities / Groundhogg / WPSEC-2026-0770

Groundhogg <= 4.9.2 - Unauthenticated Insecure Direct Object Reference to Unsent and Private Broadcast Disclosure via Campaign Archive

Medium 5.3 CWE-639Fixed in 4.9.3
ID
WPSEC-2026-0770
Plugin
Groundhogg — CRM, Newsletters, and Marketing Automation (groundhogg)
Affected
all versions before 4.9.3
Remediation
Update to 4.9.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-11
Attack surface
Groundhogg on WPSec AttackSurface
Fix released
Published

Description

The Groundhogg plugin for WordPress is vulnerable to Insecure Direct Object Reference via the campaign archive broadcast view in all versions up to, and including, 4.9.2, due to missing validation that the requested broadcast ID is a sent email broadcast belonging to the campaign in the URL. This makes it possible for unauthenticated attackers to enumerate sequential broadcast IDs under any public campaign's archive URL and read the contents of any email broadcast on the site, including unsent broadcasts and broadcasts belonging to campaigns that are not public.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0