Privilege Escalation Vulnerability in Groundhogg CRM Plugin for WordPress
CVE-2026-97644

8.8HIGH

What is CVE-2026-97644?

The Groundhogg CRM, used for newsletters and marketing automation in WordPress, has a vulnerability that allows for privilege escalation through contact identity rebinding. This flaw arises from the create_contact function in the v3 REST endpoint, which lacks adequate checks and exposes security-sensitive information. Authenticated users with Sales Representative-level access can manipulate their contact records to impersonate an Administrator through a crafted request. By exploiting this vulnerability, an attacker can gain a fully authenticated session as a WordPress Administrator, posing a serious threat to WordPress site integrity and data security.

Affected Version(s)

Groundhogg β€” CRM, Newsletters, and Marketing Automation 0 <= 4.9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez)
.