ZeroHour

CVE-2026-81660

large

Unauthenticated Stored XSS in Groundhogg WordPress Plugin

CVSS 3.1
8.8 high
EPSS
<1%p20
Published
()
Modified
AI analysis

Groundhogg — CRM, Newsletters, and Marketing Automation, a WordPress CRM and marketing automation plugin, before version 4.5.13 fails to validate or escape values submitted to some optional web form fields before storing them and displaying them back in the WordPress admin area. An unauthenticated attacker can submit a crafted payload via the site's public Groundhogg web form; when a high-privilege user such as an administrator later views the stored submission in the admin area, the injected script executes in that user's session. This lets the attacker act with administrator privileges — hijacking the admin session, creating rogue administrator accounts, altering content or settings, or exfiltrating data — consistent with the 8.8 High CVSS score. Any WordPress site running an affected version of the plugin with a public-facing Groundhogg form is exposed. There is no public proof of concept, the flaw is not in CISA KEV, and EPSS estimates only about 0.3% probability of exploitation in the next 30 days.

What to do: Update Groundhogg to version 4.5.13 or later. As an interim measure, disable or replace public-facing Groundhogg web forms and review recent form submissions for embedded HTML or script payloads; after patching, check the WordPress users list for unexpected administrator accounts and confirm high-privilege users did not interact with suspicious admin content.

Affected
Groundhogg — CRM, Newsletters, and Marketing Automation (WordPress plugin)before 4.5.13 (all versions prior to 4.5.13)
Estimated exposure
large≈20,000+ WordPress sites (approximate wordpress.org active-install count for the free Groundhogg plugin) — Groundhogg's free plugin is active on roughly 20,000 WordPress sites per wordpress.org public install counts, and the vulnerable web form handling is part of the core plugin, so most active installs with a live public form are potentially…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.