<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Groundhogg (&lt;= 4.8.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/groundhogg--4.8.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:51:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/groundhogg--4.8.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in Groundhogg WordPress Plugin via CVE-2026-92975</title><link>https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/</link><pubDate>Sat, 10 Oct 2026 07:51:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-groundhogg-priv-esc/</guid><description>The Groundhogg WordPress plugin is vulnerable to unauthorized privilege escalation due to insufficient validation of support user account credentials within the create_support_user() function.</description><content:encoded><![CDATA[<p>Groundhogg, a CRM and marketing automation plugin for WordPress, contains a high-severity privilege escalation vulnerability (CVE-2026-92975) affecting versions 4.8.3 and earlier. The flaw resides in the <code>create_support_user()</code> function, which attempts to identify a support-authorized account by checking if a user's <code>user_login</code> matches the hardcoded string 'groundhogg' and if their email matches 'support@groundhogg.io' or 'help@groundhogg.io'. Because the plugin fails to properly validate these attributes against a secure identity provider, an attacker who registers a standard account with the username 'groundhogg' and sets their email address to one of the hardcoded support constants can be automatically promoted to administrator. This promotion occurs when a legitimate site administrator interacts with the plugin's support access functionality. If the triggering administrator possesses <code>manage_network_options</code> privileges in a multisite environment, the attacker may also be granted super admin status, leading to full site takeover.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a low-privileged user to obtain administrative access to the WordPress instance. This results in the potential for complete site compromise, including the ability to execute arbitrary code, modify site content, exfiltrate sensitive CRM data, and install persistent backdoors. This vulnerability impacts all organizations running Groundhogg versions up to and including 4.8.3.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Groundhogg plugin to the latest patched version immediately.</li>
<li>Audit existing user accounts for the username 'groundhogg' and the specified hardcoded email addresses.</li>
<li>Restrict or disable open user registration on WordPress instances where the plugin is active to prevent the initial account creation required for exploitation.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>