Impact
The WordPress Groundhogg plugin for versions earlier than 4.4.1 has a broken access control flaw. The vulnerability allows a user with a subscriber role to bypass intended restrictions and perform actions reserved for users with higher privileges. This can expose or alter sensitive subscriber data, compromising the confidentiality and integrity of the system's subscription information.
Affected Systems
All installations of the WordPress Groundhogg plugin whose version is lower than 4.4.1 are affected. The vendor is Groundhogg and the product is the Groundhogg plugin used on WordPress sites to manage subscriber relationships.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, reflecting that the issue does not provide remote code execution but permits privilege escalation. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would typically exploit this flaw via an authenticated subscriber account, using the exposed functionality to gain unauthorized access. System administrators should therefore consider an update as a priority.
OpenCVE Enrichment