# Groundhogg <= 4.9.2 - Unauthenticated Insecure Direct Object Reference to Unsent and Private Broadcast Disclosure via Campaign Archive

- **ID:** WPSEC-2026-0770
- **Plugin:** Groundhogg — CRM, Newsletters, and Marketing Automation (`groundhogg`), https://wordpress.org/plugins/groundhogg/
- **Affected versions:** all versions before 4.9.3
- **Fixed in:** 4.9.3 (Update to 4.9.3 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/groundhogg
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0770/

## Description

The Groundhogg plugin for WordPress is vulnerable to Insecure Direct Object Reference via the campaign archive broadcast view in all versions up to, and including, 4.9.2, due to missing validation that the requested broadcast ID is a sent email broadcast belonging to the campaign in the URL. This makes it possible for unauthenticated attackers to enumerate sequential broadcast IDs under any public campaign's archive URL and read the contents of any email broadcast on the site, including unsent broadcasts and broadcasts belonging to campaigns that are not public.

## References

- https://wpsec.com/vuln/WPSEC-2026-0770/
- https://plugins.svn.wordpress.org/groundhogg/tags/4.9.3/
- https://wordpress.org/plugins/groundhogg/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0770/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
