Privilege Escalation in Groundhogg Plugin for WordPress
CVE-2026-92975
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-92975?
The Groundhogg plugin for WordPress is susceptible to privilege escalation resulting from inadequate validation in the create_support_user() function. This flaw allows attackers to gain elevated access by exploiting hardcoded email addresses and usernames associated with support accounts. By matching their own credentials with those constants, a user can elevate their access level to an administrator or even super administrator on multisite setups. The exploitation process necessitates that the attacker first creates a user account that mimics the hardcoded values, followed by an interaction with an administrative support feature. This serious oversight can lead to a complete takeover of the affected site if exploited.
Affected Version(s)
Groundhogg β CRM, Newsletters, and Marketing Automation 0 <= 4.8.3