Description
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Published: 2025-01-14
Score: 8.8 High
EPSS: 4.9% Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Groundhogg, a WordPress CRM plugin, permits authenticated users with Author or higher role to invoke gh_big_file_upload, which accepts any file type without validation. The lack of file type checks allows the upload of executable files such as PHP scripts, enabling an attacker to run arbitrary code on the server and gain full remote code execution authority.

Affected Systems

All installations of the trainingbusinesspros Groundhogg WordPress plugin with versions up to and including 3.7.3.5 are vulnerable. This includes any WordPress site that has the plugin at the specified or older versions.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, and an EPSS score of 5% suggests a non‑negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker who is logged in with Author level or higher can reach the file upload interface, submit a malicious file, and then trigger its execution, resulting in remote code execution. The attack vector is authenticated but the impact is system‑wide if the attacker succeeds.

Generated by OpenCVE AI on April 28, 2026 at 12:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Groundhogg plugin to the latest release that contains the fix, such as 3.7.3.6 or newer.
  • If an immediate update is not feasible, disable or limit the gh_big_file_upload capability for users with Author or higher roles, ensuring only administrators can upload files.
  • Deploy a web application firewall or file‑type filtering solution that blocks uploads of executable file types and permits only the MIME types required by the plugin.

Generated by OpenCVE AI on April 28, 2026 at 12:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-1641 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
History

Tue, 14 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 08:30:00 +0000

Type Values Removed Values Added
Description The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:16:31.781Z

Reserved: 2025-01-10T18:11:25.358Z

Link: CVE-2025-0394

cve-icon Vulnrichment

Updated: 2025-01-14T14:46:06.801Z

cve-icon NVD

Status : Deferred

Published: 2025-01-14T09:15:21.430

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-0394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T12:15:30Z

Weaknesses