SQL Injection Vulnerability in Groundhogg CRM Plugin for WordPress
CVE-2026-13333
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2026
What is CVE-2026-13333?
The Groundhogg plugin for WordPress exhibits a critical SQL Injection vulnerability due to inadequate escaping of user-supplied parameters in the 'query[select]' parameter. This issue is present in all versions up to and including 4.5.5 and allows authenticated users with Sales Representative access or higher to inject additional SQL commands into existing queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive data stored in the database, as attackers can bypass the sanitized contact query through manipulation of filter types. Organizations utilizing this plugin are advised to update to a secure version to mitigate potential data breaches.
Affected Version(s)
Groundhogg β CRM, Newsletters, and Marketing Automation 0 <= 4.5.5