CVE-2026-81660
largeUnauthenticated Stored XSS in Groundhogg WordPress Plugin
Groundhogg — CRM, Newsletters, and Marketing Automation, a WordPress CRM and marketing automation plugin, before version 4.5.13 fails to validate or escape values submitted to some optional web form fields before storing them and displaying them back in the WordPress admin area. An unauthenticated attacker can submit a crafted payload via the site's public Groundhogg web form; when a high-privilege user such as an administrator later views the stored submission in the admin area, the injected script executes in that user's session. This lets the attacker act with administrator privileges — hijacking the admin session, creating rogue administrator accounts, altering content or settings, or exfiltrating data — consistent with the 8.8 High CVSS score. Any WordPress site running an affected version of the plugin with a public-facing Groundhogg form is exposed. There is no public proof of concept, the flaw is not in CISA KEV, and EPSS estimates only about 0.3% probability of exploitation in the next 30 days.
What to do: Update Groundhogg to version 4.5.13 or later. As an interim measure, disable or replace public-facing Groundhogg web forms and review recent form submissions for embedded HTML or script payloads; after patching, check the WordPress users list for unexpected administrator accounts and confirm high-privilege users did not interact with suspicious admin content.
| Groundhogg — CRM, Newsletters, and Marketing Automation (WordPress plugin) | before 4.5.13 (all versions prior to 4.5.13) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.