Impact
The vulnerability is an IDOR flaw that allows an attacker with a valid user session to subvert authentication controls and retrieve or modify data that should be restricted. Because the flaw lies in the plugin’s handling of user-controlled keys, a compromised or malicious user can potentially expose sensitive records or alter existing entries, resulting in confidentiality and integrity violations.
Affected Systems
WordPress installations running the Groundhogg HollerBox plugin version 2.3.14 or earlier are affected. The issue occurs within the plugin’s PHP code that processes user input for data retrieval and updates, and is present from the earliest build up to 2.3.14.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. No EPSS score is provided, and the vulnerability is not listed in CISA KEV. The likely attack vector is a web-based request where an authenticated user submits a crafted parameter to the plugin’s endpoints, bypassing proper authorization checks. Exploits would be limited to the scope of the plugin’s data but could still lead to significant information leakage if sensitive content is stored there.
OpenCVE Enrichment