{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agroundhogggroundhoggwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:groundhogg:groundhogg:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-97644"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Groundhogg — CRM, Newsletters, and Marketing Automation (\u003c= 4.9)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","wordpress","web-application"],"_cs_type":"advisory","_cs_vendors":["Groundhogg"],"content_html":"\u003cp\u003eThe Groundhogg plugin for WordPress (versions 4.9 and earlier) contains a critical vulnerability (CVE-2026-97644) that enables authenticated users with the 'add_contacts' capability (such as Sales Representatives) to escalate privileges to Administrator. The issue resides in the v3 REST endpoint \u003ccode\u003ePOST /gh/v3/contacts\u003c/code\u003e, where the \u003ccode\u003ecreate_contact\u003c/code\u003e function fails to restrict the \u003ccode\u003euser_id\u003c/code\u003e field. By manipulating the request payload, an attacker can rebind a contact record to an administrative user ID.\u003c/p\u003e\n\u003cp\u003eOnce the contact record is rebound, the attacker can interact with the v4 email-test endpoint (\u003ccode\u003ePOST /gh/v4/emails/test\u003c/code\u003e), which is accessible to users with the 'send_emails' capability. This endpoint generates an \u003ccode\u003eauto_login_url\u003c/code\u003e bound to the contact record. By consuming this one-time permissions key, the attacker forces the system to call \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e, granting them a fully authenticated administrative session. This vulnerability poses a severe risk to WordPress instances utilizing the plugin for marketing automation and CRM purposes, as it provides a clear path to complete site takeover by low-privileged users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the WordPress instance with at least 'Sales Representative' or equivalent privileges.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a \u003ccode\u003ePOST\u003c/code\u003e request to the Groundhogg v3 API endpoint \u003ccode\u003e/gh/v3/contacts\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker includes the \u003ccode\u003euser_id\u003c/code\u003e field in the request payload, targeting the ID associated with a WordPress Administrator.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecreate_contact\u003c/code\u003e function performs an upsert operation that overwrites the existing contact record association.\u003c/li\u003e\n\u003cli\u003eAttacker sends a \u003ccode\u003ePOST\u003c/code\u003e request to the v4 email-test endpoint at \u003ccode\u003e/gh/v4/emails/test\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe plugin generates an \u003ccode\u003eauto_login_url\u003c/code\u003e mapped to the now-rebound administrative contact.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves the auto-login URL from the test notification.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the URL, triggering \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e and establishing an authenticated session as the Administrator.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative access to the affected WordPress installation. This allows an attacker to execute arbitrary code, modify site content, access sensitive customer data stored within the CRM, and install malicious plugins or backdoors, leading to total compromise of the web application and its underlying data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch immediately: Upgrade the Groundhogg plugin to the version containing the fix for CVE-2026-97644.\u003c/li\u003e\n\u003cli\u003eAudit logs for the specified REST endpoints: Monitor web server access logs for \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/gh/v3/contacts\u003c/code\u003e and \u003ccode\u003e/gh/v4/emails/test\u003c/code\u003e originating from non-administrative user accounts.\u003c/li\u003e\n\u003cli\u003eRestrict access: Limit WordPress user capabilities to ensure only trusted users hold the 'add_contacts' and 'send_emails' privileges until patching is completed.\u003c/li\u003e\n\u003cli\u003eReview administrative accounts: Audit all WordPress user accounts for suspicious additions or modifications to user profiles performed after the vulnerability was publicly disclosed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T04:53:43Z","date_published":"2026-10-03T04:53:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/","summary":"Authenticated attackers can perform privilege escalation in Groundhogg versions 4.9 and below by rebinding contact records to arbitrary user IDs via the REST API and leveraging automated login links.","title":"Privilege Escalation in Groundhogg WordPress Plugin via Contact Rebinding","url":"https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:groundhogg:groundhogg:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}