{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/groundhogg--4.8.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:groundhogg:groundhogg:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92975"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Groundhogg (\u003c= 4.8.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Groundhogg"],"content_html":"\u003cp\u003eGroundhogg, a CRM and marketing automation plugin for WordPress, contains a high-severity privilege escalation vulnerability (CVE-2026-92975) affecting versions 4.8.3 and earlier. The flaw resides in the \u003ccode\u003ecreate_support_user()\u003c/code\u003e function, which attempts to identify a support-authorized account by checking if a user's \u003ccode\u003euser_login\u003c/code\u003e matches the hardcoded string 'groundhogg' and if their email matches 'support@groundhogg.io' or 'help@groundhogg.io'. Because the plugin fails to properly validate these attributes against a secure identity provider, an attacker who registers a standard account with the username 'groundhogg' and sets their email address to one of the hardcoded support constants can be automatically promoted to administrator. This promotion occurs when a legitimate site administrator interacts with the plugin's support access functionality. If the triggering administrator possesses \u003ccode\u003emanage_network_options\u003c/code\u003e privileges in a multisite environment, the attacker may also be granted super admin status, leading to full site takeover.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged user to obtain administrative access to the WordPress instance. This results in the potential for complete site compromise, including the ability to execute arbitrary code, modify site content, exfiltrate sensitive CRM data, and install persistent backdoors. This vulnerability impacts all organizations running Groundhogg versions up to and including 4.8.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Groundhogg plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts for the username 'groundhogg' and the specified hardcoded email addresses.\u003c/li\u003e\n\u003cli\u003eRestrict or disable open user registration on WordPress instances where the plugin is active to prevent the initial account creation required for exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T07:51:37Z","date_published":"2026-10-10T07:51:37Z","id":"https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/","summary":"The Groundhogg WordPress plugin is vulnerable to unauthorized privilege escalation due to insufficient validation of support user account credentials within the create_support_user() function.","title":"Privilege Escalation in Groundhogg WordPress Plugin via CVE-2026-92975","url":"https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Groundhogg (\u003c= 4.8.3)","version":"https://jsonfeed.org/version/1.1"}