Privilege Escalation Vulnerability in Groundhogg CRM Plugin for WordPress
CVE-2026-97644
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-97644?
The Groundhogg CRM, used for newsletters and marketing automation in WordPress, has a vulnerability that allows for privilege escalation through contact identity rebinding. This flaw arises from the create_contact function in the v3 REST endpoint, which lacks adequate checks and exposes security-sensitive information. Authenticated users with Sales Representative-level access can manipulate their contact records to impersonate an Administrator through a crafted request. By exploiting this vulnerability, an attacker can gain a fully authenticated session as a WordPress Administrator, posing a serious threat to WordPress site integrity and data security.
Affected Version(s)
Groundhogg β CRM, Newsletters, and Marketing Automation 0 <= 4.9