Privilege Escalation in Groundhogg Plugin for WordPress
CVE-2026-92975

8.1HIGH

What is CVE-2026-92975?

The Groundhogg plugin for WordPress is susceptible to privilege escalation resulting from inadequate validation in the create_support_user() function. This flaw allows attackers to gain elevated access by exploiting hardcoded email addresses and usernames associated with support accounts. By matching their own credentials with those constants, a user can elevate their access level to an administrator or even super administrator on multisite setups. The exploitation process necessitates that the attacker first creates a user account that mimics the hardcoded values, followed by an interaction with an administrative support feature. This serious oversight can lead to a complete takeover of the affected site if exploited.

Affected Version(s)

Groundhogg β€” CRM, Newsletters, and Marketing Automation 0 <= 4.8.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.