Path Traversal Vulnerability in Groundhogg by WordPress
CVE-2026-85310

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 September 2026

What is CVE-2026-85310?

A path traversal vulnerability in versions of Groundhogg up to 4.7.1 allows attackers to gain unauthorized access to sensitive files on the server. By exploiting this flaw, an attacker can manipulate file paths to access files outside the intended directories, posing significant risks to data integrity and confidentiality. Users are urged to update their plugins to mitigate risks associated with potential exploitation.

Affected Version(s)

Groundhogg <= 4.7.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergei Pro | Patchstack Bug Bounty Program
.