← WordPress Vulnerabilities
WordPress security by component

Groundhogg — CRM, Newsletters, and Marketing Automation

Groundhogg — CRM, Newsletters, and Marketing Automation adds customer relationship management, newsletters, funnels, and marketing automation features to WordPress.

Groundhogg — CRM, Newsletters, and Marketing Automation (groundhogg-crm-newsletters-and-marketing-automation) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2026; the highest published CVSS base score is 8.8.

Plugin slug: groundhogg-crm-newsletters-and-marketing-automation

CVE-2026-81741: Groundhogg redirects email-preference confirmations to attacker-selected URLs

Groundhogg before 4.7.2 does not constrain email-preference confirmation redirects to the site's host. An unauthenticated attacker can craft a link that redirects a visitor to an external destination, making the site's trusted address usable as a step in a phishing lure.

PublishedSep 09, 2026
Known safe version4.7.2
Published vulnerabilities for groundhogg-crm-newsletters-and-marketing-automation
Safe version
Sep 09, 2026 CVE-2026-81741
Groundhogg redirects email-preference confirmations to attacker-selected URLs
Groundhogg before 4.7.2 does not constrain email-preference confirmation redirects to the site's host. An unauthenticated attacker can craft a link that redirects a visitor to an external destination, making the site's trusted address usable as a step in a phishing lure.
4.7.2
CVE4.7
NVDPending
Aug 30, 2026 CVE-2026-81660
Groundhogg web forms permit unauthenticated stored XSS against administrators
Groundhogg before 4.5.13 does not validate or escape values submitted through some optional web form fields before storing and rendering them in an administrative area. An unauthenticated visitor can submit script content that executes when a high-privilege user views the affected data.
4.5.13
CVE8.8
NVDPending
Nov 21, 2025 CVE-2025-12750
Groundhogg — CRM, Newsletters, and Marketing Automation: SQL injection
Groundhogg — CRM, Newsletters, and Marketing Automation is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending