{
 "id": "WPSEC-2026-0770",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0770/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0770/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0770/index.md",
 "title": "Groundhogg <= 4.9.2 - Unauthenticated Insecure Direct Object Reference to Unsent and Private Broadcast Disclosure via Campaign Archive",
 "description": "The Groundhogg plugin for WordPress is vulnerable to Insecure Direct Object Reference via the campaign archive broadcast view in all versions up to, and including, 4.9.2, due to missing validation that the requested broadcast ID is a sent email broadcast belonging to the campaign in the URL. This makes it possible for unauthenticated attackers to enumerate sequential broadcast IDs under any public campaign's archive URL and read the contents of any email broadcast on the site, including unsent broadcasts and broadcasts belonging to campaigns that are not public.",
 "plugin": {
  "slug": "groundhogg",
  "name": "Groundhogg",
  "full_name": "Groundhogg — CRM, Newsletters, and Marketing Automation",
  "wordpress_org": "https://wordpress.org/plugins/groundhogg/",
  "advisories_url": "https://wpsec.com/vuln/plugin/groundhogg/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/groundhogg"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.9.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.9.3"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.9.3",
 "remediation": "Update to 4.9.3 or later.",
 "fix_released": "2026-10-10T12:11:21+00:00",
 "published": "2026-10-11T12:43:38+00:00",
 "updated": "2026-10-11T11:41:34.021368+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0770/",
  "https://plugins.svn.wordpress.org/groundhogg/tags/4.9.3/",
  "https://wordpress.org/plugins/groundhogg/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/groundhogg",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-11"
 }
}