Impact
The Groundhogg plugin does not validate or escape values submitted to optional web form fields such as dropdown or radio controls before storing them and later rendering them in an administrative area. This flaw allows an unauthenticated user to submit malicious script content that is persisted and executed when a high‑privilege user views the form. The execution of the injected code can compromise the confidentiality or integrity of the administration interface, potentially enabling further actions by the attacker within that privileged context.
Affected Systems
This vulnerability affects all installations of the Groundhogg WordPress plugin with a version number earlier than 4.5.13. Site administrators should examine any public Groundhogg forms that employ the vulnerable dropdown or radio fields to determine whether the affected code path is present.
Risk and Exploitability
The CVE has no EPSS score and is not listed in CISA’s KEV catalog. The vulnerability can be exploited by simply submitting a crafted value to a publicly accessible Groundhogg form; no authentication is required to trigger the stored XSS. Because a high‑privilege user subsequently receives malicious code execution when accessing the administrative view, the risk is high. Immediate action is warranted to prevent attackers from leveraging this flaw.
OpenCVE Enrichment