PT-2026-68013 · WordPress · Groundhogg

·

CVE-2026-11454

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Groundhogg — CRM, Newsletters, and Marketing Automation versions prior to 4.5.3
Description An Insecure Direct Object Reference exists in the plugin via the 'GET /wp-json/gh/v4/contacts/' REST endpoint. The permission callback for this endpoint only verifies the role-level view contacts capability, and the read single() function returns full contact records using sequential integer IDs without performing an object-level ownership check. This allows authenticated users with the view contacts capability but without the view others contacts capability, such as those assigned the Sales Rep role, to access any contact record on the site. Exposed data includes personally identifiable information (PII), contact meta, owner IDs, admin edit URLs, and the full capability set of linked WordPress users.
Recommendations Update the plugin to version 4.5.3 or later. As a temporary mitigation, restrict access to the 'GET /wp-json/gh/v4/contacts/' REST endpoint for users with the Sales Rep role.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11454

Affected Products

Groundhogg