WordPress security by component
Groundhogg — CRM, Newsletters, and Marketing Automation
Plugin description
Groundhogg — CRM, Newsletters, and Marketing Automation adds customer relationship management, newsletters, funnels, and marketing automation features to WordPress.
Groundhogg — CRM, Newsletters, and Marketing Automation (groundhogg-crm-newsletters-and-marketing-automation) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
groundhogg-crm-newsletters-and-marketing-automationLatest vulnerability
CVE-2026-81741: Groundhogg redirects email-preference confirmations to attacker-selected URLs
Groundhogg before 4.7.2 does not constrain email-preference confirmation redirects to the site's host. An unauthenticated attacker can craft a link that redirects a visitor to an external destination, making the site's trusted address usable as a step in a phishing lure.
| Safe version |
|
||
|---|---|---|---|
| Sep 09, 2026 |
CVE-2026-81741
Groundhogg redirects email-preference confirmations to attacker-selected URLs
Groundhogg before 4.7.2 does not constrain email-preference confirmation redirects to the site's host. An unauthenticated attacker can craft a link that redirects a visitor to an external destination, making the site's trusted address usable as a step in a phishing lure.
|
4.7.2 |
CVE4.7
NVDPending
|
| Aug 30, 2026 |
CVE-2026-81660
Groundhogg web forms permit unauthenticated stored XSS against administrators
Groundhogg before 4.5.13 does not validate or escape values submitted through some optional web form fields before storing and rendering them in an administrative area. An unauthenticated visitor can submit script content that executes when a high-privilege user views the affected data.
|
4.5.13 |
CVE8.8
NVDPending
|
| Nov 21, 2025 |
CVE-2025-12750
Groundhogg — CRM, Newsletters, and Marketing Automation: SQL injection
Groundhogg — CRM, Newsletters, and Marketing Automation is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVDPending
|