Description
Authorization Bypass Through User-Controlled Key vulnerability in Groundhogg HollerBox holler-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HollerBox: from n/a through 2.3.14.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Insecure Direct Object Reference leading to unauthorized data access
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an IDOR flaw that allows an attacker with a valid user session to subvert authentication controls and retrieve or modify data that should be restricted. Because the flaw lies in the plugin’s handling of user-controlled keys, a compromised or malicious user can potentially expose sensitive records or alter existing entries, resulting in confidentiality and integrity violations.

Affected Systems

WordPress installations running the Groundhogg HollerBox plugin version 2.3.14 or earlier are affected. The issue occurs within the plugin’s PHP code that processes user input for data retrieval and updates, and is present from the earliest build up to 2.3.14.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. No EPSS score is provided, and the vulnerability is not listed in CISA KEV. The likely attack vector is a web-based request where an authenticated user submits a crafted parameter to the plugin’s endpoints, bypassing proper authorization checks. Exploits would be limited to the scope of the plugin’s data but could still lead to significant information leakage if sensitive content is stored there.

Generated by OpenCVE AI on October 8, 2026 at 14:42 UTC.

Remediation

Vendor Solution

Update the WordPress HollerBox plugin to the latest available version (at least 2.3.15).


OpenCVE Recommended Actions

  • Upgrade the HollerBox plugin to version 2.3.15 or later, which contains the authorization fix.
  • If an upgrade cannot be performed immediately, restrict the plugin’s capabilities by reviewing WordPress role settings to ensure only trusted users can access its features.
  • Remove or archive any residual plugin files from version 2.3.14 that may still reside on the server to eliminate possible fallback entry points.

Generated by OpenCVE AI on October 8, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Groundhogg HollerBox holler-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HollerBox: from n/a through 2.3.14.
Title WordPress HollerBox plugin <= 2.3.14 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T17:54:09.175Z

Reserved: 2026-10-07T00:21:31.996Z

Link: CVE-2026-106603

cve-icon Vulnrichment

Updated: 2026-10-08T15:28:34.899Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T13:17:14.877

Modified: 2026-10-08T18:17:15.260

Link: CVE-2026-106603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key