← WordPress Vulnerabilities
WordPress security by component

Groundhogg — CRM, Newsletters, and Marketing Automation

Groundhogg — CRM, Newsletters, and Marketing Automation is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Nov 21, 2025; the highest CVE/CNA score is 4.9.

Plugin slug: groundhogg-crm-newsletters-and-marketing-automation

CVE-2025-12750: Groundhogg — CRM, Newsletters, and Marketing Automation: SQL injection

Groundhogg — CRM, Newsletters, and Marketing Automation is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.

PublishedNov 21, 2025
Safe version guidanceSee mitigation notes
Safe version
Nov 21, 2025 CVE-2025-12750
Groundhogg — CRM, Newsletters, and Marketing Automation: SQL injection
Groundhogg — CRM, Newsletters, and Marketing Automation is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending