SQL Injection Vulnerability in Groundhogg Plugin for WordPress
CVE-2026-13331
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2026
What is CVE-2026-13331?
The Groundhogg plugin for WordPress is susceptible to SQL Injection through the 'search' parameter, affecting all versions prior to 4.5.5. This vulnerability arises from inadequate escaping of user-supplied input and the lack of sufficient preparation in the underlying SQL query structure. Authenticated attackers with marketer-level permissions or higher can exploit this weakness to inject malicious SQL queries, which may lead to unauthorized access to sensitive data stored in the database.
Affected Version(s)
Groundhogg β CRM, Newsletters, and Marketing Automation 0 <= 4.5.5