Executive brief
HollerBox, a WordPress plugin used for lead generation and popups, contains a security flaw that allows unauthorized individuals to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack sessions, redirect users to malicious websites, or deface the site. This could lead to a loss of customer trust and unauthorized access to administrative functions.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the HollerBox plugin for WordPress (versions 2.3.10.1 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or site defacement. The issue is resolved in version 2.3.11.
Affected products
- Groundhogg HollerBox <= 2.3.10.1
Timeline
- 2026-04-19: other: Reported by researcher she11f
- 2026-06-02: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date
- 2026-06-02: patched: Version 2.3.11 released