Privilege Escalation Vulnerability in Groundhogg CRM Plugin for WordPress
CVE-2026-104725
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104725?
The Groundhogg CRM plugin for WordPress presents a privilege escalation risk due to inadequate ownership and capability checks on the user parameter within the process_edit() function. Authenticated users with edit_contacts capability are able to reassess contact records, linking them to any arbitrary WordPress user account. This vulnerability permits users with specific roles, such as sales_rep, to elevate their privileges to administrator level through a series of steps involving the creation of a note containing an auto-login link for the targeted administrator. By exploiting this flow, attackers can gain unauthorized access to administrative functionalities, putting sensitive data at risk.
Affected Version(s)
Groundhogg β CRM, Newsletters, and Marketing Automation 0 <= 4.9