<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:groundhogg:groundhogg:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agroundhogggroundhoggwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:53:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agroundhogggroundhoggwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in Groundhogg WordPress Plugin via Contact Rebinding</title><link>https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/</link><pubDate>Sat, 03 Oct 2026 04:53:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/</guid><description>Authenticated attackers can perform privilege escalation in Groundhogg versions 4.9 and below by rebinding contact records to arbitrary user IDs via the REST API and leveraging automated login links.</description><content:encoded><![CDATA[<p>The Groundhogg plugin for WordPress (versions 4.9 and earlier) contains a critical vulnerability (CVE-2026-97644) that enables authenticated users with the 'add_contacts' capability (such as Sales Representatives) to escalate privileges to Administrator. The issue resides in the v3 REST endpoint <code>POST /gh/v3/contacts</code>, where the <code>create_contact</code> function fails to restrict the <code>user_id</code> field. By manipulating the request payload, an attacker can rebind a contact record to an administrative user ID.</p>
<p>Once the contact record is rebound, the attacker can interact with the v4 email-test endpoint (<code>POST /gh/v4/emails/test</code>), which is accessible to users with the 'send_emails' capability. This endpoint generates an <code>auto_login_url</code> bound to the contact record. By consuming this one-time permissions key, the attacker forces the system to call <code>wp_set_auth_cookie()</code>, granting them a fully authenticated administrative session. This vulnerability poses a severe risk to WordPress instances utilizing the plugin for marketing automation and CRM purposes, as it provides a clear path to complete site takeover by low-privileged users.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates to the WordPress instance with at least 'Sales Representative' or equivalent privileges.</li>
<li>Attacker crafts a <code>POST</code> request to the Groundhogg v3 API endpoint <code>/gh/v3/contacts</code>.</li>
<li>Attacker includes the <code>user_id</code> field in the request payload, targeting the ID associated with a WordPress Administrator.</li>
<li>The <code>create_contact</code> function performs an upsert operation that overwrites the existing contact record association.</li>
<li>Attacker sends a <code>POST</code> request to the v4 email-test endpoint at <code>/gh/v4/emails/test</code>.</li>
<li>The plugin generates an <code>auto_login_url</code> mapped to the now-rebound administrative contact.</li>
<li>Attacker retrieves the auto-login URL from the test notification.</li>
<li>Attacker accesses the URL, triggering <code>wp_set_auth_cookie()</code> and establishing an authenticated session as the Administrator.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative access to the affected WordPress installation. This allows an attacker to execute arbitrary code, modify site content, access sensitive customer data stored within the CRM, and install malicious plugins or backdoors, leading to total compromise of the web application and its underlying data.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Patch immediately: Upgrade the Groundhogg plugin to the version containing the fix for CVE-2026-97644.</li>
<li>Audit logs for the specified REST endpoints: Monitor web server access logs for <code>POST</code> requests to <code>/gh/v3/contacts</code> and <code>/gh/v4/emails/test</code> originating from non-administrative user accounts.</li>
<li>Restrict access: Limit WordPress user capabilities to ensure only trusted users hold the 'add_contacts' and 'send_emails' privileges until patching is completed.</li>
<li>Review administrative accounts: Audit all WordPress user accounts for suspicious additions or modifications to user profiles performed after the vulnerability was publicly disclosed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>wordpress</category><category>web-application</category></item></channel></rss>