Junglewise Threat Intelligence

CVE-2026-48885: Groundhogg HollerBox unauthenticated XSS

CVE-2026-48885 · Severity: high · CVSS 7.1 · Published 2026-06-15

Vendors: Groundhogg.

Executive brief

HollerBox, a WordPress plugin used for lead generation and popups, contains a security flaw that allows unauthorized individuals to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack sessions, redirect users to malicious websites, or deface the site. This could lead to a loss of customer trust and unauthorized access to administrative functions.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the HollerBox plugin for WordPress (versions 2.3.10.1 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or site defacement. The issue is resolved in version 2.3.11.

Affected products

  • Groundhogg HollerBox <= 2.3.10.1

Timeline

  • 2026-04-19: other: Reported by researcher she11f
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-02: patched: Version 2.3.11 released

References