CVE-2023-2714: Groundhogg <= 2.7.9.8 - Missing Authorization to Update License
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'checklicense' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the license key and support license key, but it can only be changed to a valid license key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2714?
CVE-2023-2714 is a vulnerability in the Groundhogg plugin for WordPress that allows authenticated attackers to modify data without proper authorization.
Which versions of the Groundhogg plugin are affected by CVE-2023-2714?
Versions up to and including 2.7.9.8 of the Groundhogg plugin for WordPress are affected by CVE-2023-2714.
What is the severity of CVE-2023-2714?
CVE-2023-2714 has a severity rating of medium (4.3).
How can authenticated attackers exploit CVE-2023-2714?
Authenticated attackers with subscriber-level permissions and above can exploit CVE-2023-2714 to modify data without proper authorization.
Is there a fix for CVE-2023-2714?
Yes, the Groundhogg plugin has released a fix in version 2.7.10 to address the vulnerability CVE-2023-2714.