Impact
A blind SQL injection vulnerability exists in the Groundhogg WordPress plugin up to and including version 4.8.3. The flaw stems from insufficient neutralization of user input that is later incorporated into SQL commands, allowing an attacker to probe or extract data from the database without receiving immediate error messages. The consequence is the unauthorized disclosure of sensitive content such as user credentials, contact information, and internal application data, as well as the potential for further exploitation if additional logical weaknesses exist.
Affected Systems
This issue affects installations of the Groundhogg plugin for WordPress that are at or below version 4.8.3. Any site using those versions is subject to the risk, while the update to 4.9 or newer eliminates the vulnerability.
Risk and Exploitability
With a CVSS score of 7.6 the vulnerability is considered high severity. The EPSS score is not available, indicating that no publicly available exploitation data has been reported yet, and the vulnerability is not currently listed in CISA KEV. Assuming the plugin is exposed to externally accessible forms or URLs, an attacker could perform a blind injection attack by sending carefully crafted queries and interpreting response timing or boolean outcomes to extract data. No additional system compromises are required beyond the initial attempt to read database content.
OpenCVE Enrichment