Impact
The Groundhogg WordPress plugin prior to version 4.7.2 allows an attacker to supply an arbitrary redirect_to URL in the email preference confirmation flow that is not constrained to the site’s own domain. This unsanitized redirect can lead to open redirect exploitation, which may be leveraged for phishing, malware delivery or loss of user trust. The weakness originates from inadequate host validation, resulting in a classic open redirect (CWE-601).
Affected Systems
Sites running the Groundhogg CRM, Newsletters and Marketing Automation plugin on WordPress with a plugin version earlier than 4.7.2 are impacted. The plugin is distributed as a WordPress plugin and can be installed on any WordPress installation that has not applied the security update.
Risk and Exploitability
The flaw is exploitable without authentication; a crafted link can be embedded in email, social media or other public channels and will redirect unsuspecting visitors to a malicious site. The CVSS score of 4.7 indicates medium severity, while the EPSS score of < 1% suggests a low probability of exploitation. Although not listed in the CISA KEV catalog, its ease of exploitation and potential for social engineering give it a moderate risk rating. The likely attack vector is an unsolicited link sent to users of the affected WordPress site.
OpenCVE Enrichment