---
id: CVE-2026-81741
title: >-
  The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin
  before 4.7.2 does not restrict the redirect target of its email preference
  confirmation flow to the site's own host, allowing unauthenticated attackers
  to redir…
summary: >-
  The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin
  before 4.7.2 does not restrict the redirect target of its email preference
  confirmation flow to the site's own host, allowing unauthenticated attackers
  to redir…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'
cwe:
  - CWE-601
product: 'Groundhogg — CRM, Newsletters, and Marketing Automation'
affected:
  - groundhogg_crm_newsletters_and_marketing_automation < 4.7.2
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:17:10.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81741'
references:
  - url: 'https://wpscan.com/vulnerability/4bfdee51-f2d0-4549-a9b4-5f4e11f2de4c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T15:33:30.604748Z'
epss: 0.0029
epssPercentile: 0.19193
ingestedAt: '2026-09-09T07:03:03.592Z'
---

## Overview

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
