SQL Injection Vulnerability in Groundhogg CRM Plugin for WordPress
CVE-2026-13333

6.5MEDIUM

What is CVE-2026-13333?

The Groundhogg plugin for WordPress exhibits a critical SQL Injection vulnerability due to inadequate escaping of user-supplied parameters in the 'query[select]' parameter. This issue is present in all versions up to and including 4.5.5 and allows authenticated users with Sales Representative access or higher to inject additional SQL commands into existing queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive data stored in the database, as attackers can bypass the sanitized contact query through manipulation of filter types. Organizations utilizing this plugin are advised to update to a secure version to mitigate potential data breaches.

Affected Version(s)

Groundhogg β€” CRM, Newsletters, and Marketing Automation 0 <= 4.5.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland
PRISM
.