Unauthorized Data Modification Vulnerability in Groundhogg Plugin for WordPress
CVE-2023-2715
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 20 May 2023
What is CVE-2023-2715?
The Groundhogg plugin for WordPress presents a security risk due to an insufficient capability check in its 'submit_ticket' function. This vulnerability allows authenticated users to execute unauthorized modifications, enabling them to create support tickets that potentially exfiltrate sensitive data to the plugin developer. Additionally, attackers could generate admin access using an auto login link included in the ticket, heightening the threat if the plugin is active under a valid license. Website administrators should promptly update to the latest version to mitigate exposure.
Affected Version(s)
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg * <= 2.7.8.9