Stored Cross-Site Scripting Vulnerability in Groundhogg Plugin for WordPress
CVE-2025-1267
5.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 April 2025
What is CVE-2025-1267?
The Groundhogg plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'label' parameter due to a lack of adequate input sanitization and output escaping. This issue impacts versions up to and including 3.7.4.1 and primarily affects multi-site installations where 'unfiltered_html' has been disabled. Authenticated attackers with Administrator-level access could exploit this vulnerability to inject arbitrary web scripts into pages that execute when unsuspecting users visit the compromised pages. It is crucial for site administrators to review and update their Groundhogg plugin to mitigate this risk.
Affected Version(s)
Groundhogg β CRM, Newsletters, and Marketing Automation 0 <= 3.7.4.1