CVE-2026-97644High· 8.8▾ TwilightThe Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the create_contact function in the v3 REST endpoint (POST /gh/v3/contacts) is gated solely by the add_contacts capability and forwards the full request payload — including the security-bearing user_id column — into the upsert path of Contacts_DB::add(), which bypasses the ownership guard that Contacts_DB::update() enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (POST /gh/v4/emails/test) — also accessible to the Sales Representative role via the send_emails capability — to generate an {auto_login_url} one-time permissions key bound to the rebound contact, and consume that link to call wp_set_auth_cookie() and gain a fully authenticated session as the WordPress Administrator.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81741Medium· 4.7The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redir…
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2026-104854High· 8.5Nx is a monorepo solution for TypeScript and polyglot codebases
CVE-2026-19652Critical· 9.8The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0
CVE-2026-104412Medium· 4.3Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so