Impact
A path traversal flaw appears in the import_contacts routine of the WordPress Groundhogg plugin. The flaw allows an attacker to read files on the web server that lie outside the intended import directory, potentially exposing configuration files, credentials, or other sensitive information. Because this is a file read vulnerability, it primarily threatens confidentiality. The weakness is categorized as CWE‑35.
Affected Systems
The vulnerability affects the Groundhogg plugin developed by Adrian Tobey for WordPress. All releases up to and including version 4.7.1 are impacted; later releases are not known to contain the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting that mass exploitation has not yet been observed. The attack vector appears to be an authenticated request to the import_contacts endpoint, which may be restricted to users with certain roles. Successful exploitation would allow reading arbitrary files, posing a significant confidentiality risk.
OpenCVE Enrichment