Privilege Escalation in Groundhogg WordPress Plugin via Contact Rebinding
Authenticated attackers can perform privilege escalation in Groundhogg versions 4.9 and below by rebinding contact records to arbitrary user IDs via the REST API and leveraging automated login links.
CVE search metadata
CVE search record: CVE-2026-97644. Severity: high. CVSS: 8.8. KEV: no. Product: Groundhogg — CRM, Newsletters, and Marketing Automation (<= 4.9). Brief: Privilege Escalation in Groundhogg WordPress Plugin via Contact Rebinding. Brief link: https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/
The Groundhogg plugin for WordPress (versions 4.9 and earlier) contains a critical vulnerability (CVE-2026-97644) that enables authenticated users with the 'add_contacts' capability (such as Sales Representatives) to escalate privileges to Administrator. The issue resides in the v3 REST endpoint POST /gh/v3/contacts, where the create_contact function fails to restrict the user_id field. By manipulating the request payload, an attacker can rebind a contact record to an administrative user ID.
Once the contact record is rebound, the attacker can interact with the v4 email-test endpoint (POST /gh/v4/emails/test), which is accessible to users with the 'send_emails' capability. This endpoint generates an auto_login_url bound to the contact record. By consuming this one-time permissions key, the attacker forces the system to call wp_set_auth_cookie(), granting them a fully authenticated administrative session. This vulnerability poses a severe risk to WordPress instances utilizing the plugin for marketing automation and CRM purposes, as it provides a clear path to complete site takeover by low-privileged users.
Attack Chain
- Attacker authenticates to the WordPress instance with at least 'Sales Representative' or equivalent privileges.
- Attacker crafts a
POSTrequest to the Groundhogg v3 API endpoint/gh/v3/contacts. - Attacker includes the
user_idfield in the request payload, targeting the ID associated with a WordPress Administrator. - The
create_contactfunction performs an upsert operation that overwrites the existing contact record association. - Attacker sends a
POSTrequest to the v4 email-test endpoint at/gh/v4/emails/test. - The plugin generates an
auto_login_urlmapped to the now-rebound administrative contact. - Attacker retrieves the auto-login URL from the test notification.
- Attacker accesses the URL, triggering
wp_set_auth_cookie()and establishing an authenticated session as the Administrator.
Impact
Successful exploitation results in full administrative access to the affected WordPress installation. This allows an attacker to execute arbitrary code, modify site content, access sensitive customer data stored within the CRM, and install malicious plugins or backdoors, leading to total compromise of the web application and its underlying data.
Recommendation
Prioritized actions for security teams:
- Patch immediately: Upgrade the Groundhogg plugin to the version containing the fix for CVE-2026-97644.
- Audit logs for the specified REST endpoints: Monitor web server access logs for
POSTrequests to/gh/v3/contactsand/gh/v4/emails/testoriginating from non-administrative user accounts. - Restrict access: Limit WordPress user capabilities to ensure only trusted users hold the 'add_contacts' and 'send_emails' privileges until patching is completed.
- Review administrative accounts: Audit all WordPress user accounts for suspicious additions or modifications to user profiles performed after the vulnerability was publicly disclosed.
Immediate actions
Upgrade Groundhogg to a version patched against CVE-2026-97644
Threat Hunt
Search logs for POST /gh/v3/contacts with user_id parameter
Data: webserver_logs
Mitigations
Upgrade Groundhogg plugin
CVE-2026-97644
Detection coverage 1
Detects CVE-2026-97644 Exploitation - Unauthorized Contact Upsert
highDetects potential exploitation of CVE-2026-97644 by identifying POST requests to the Groundhogg contact API containing a user_id parameter.
Detection queries are available on the platform. Get full rules →