SQL Injection Vulnerability in Groundhogg CRM Plugin for WordPress
CVE-2026-14029

6.5MEDIUM

What is CVE-2026-14029?

The Groundhogg CRM, Newsletters, and Marketing Automation plugin for WordPress is susceptible to SQL Injection due to a lack of proper input sanitization in the 'select' parameter. This vulnerability affects all versions up to and including 4.5.8 and allows authenticated users with custom access roles to inject additional SQL queries. By exploiting this vulnerability, attackers can retrieve sensitive database information, compromising user data and privacy. Proper measures should be implemented to ensure that user inputs are securely handled and existing SQL queries are adequately prepared to prevent such security risks.

Affected Version(s)

Groundhogg β€” CRM, Newsletters, and Marketing Automation 0 <= 4.5.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PRISM
.