Impact
Groundhogg, a WordPress CRM plugin, permits authenticated users with Author or higher role to invoke gh_big_file_upload, which accepts any file type without validation. The lack of file type checks allows the upload of executable files such as PHP scripts, enabling an attacker to run arbitrary code on the server and gain full remote code execution authority.
Affected Systems
All installations of the trainingbusinesspros Groundhogg WordPress plugin with versions up to and including 3.7.3.5 are vulnerable. This includes any WordPress site that has the plugin at the specified or older versions.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and an EPSS score of 5% suggests a non‑negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker who is logged in with Author level or higher can reach the file upload interface, submit a malicious file, and then trigger its execution, resulting in remote code execution. The attack vector is authenticated but the impact is system‑wide if the attacker succeeds.
OpenCVE Enrichment
EUVD