Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.
Published: 2026-10-05
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch
AI Analysis

Impact

A blind SQL injection vulnerability exists in the Groundhogg WordPress plugin up to and including version 4.8.3. The flaw stems from insufficient neutralization of user input that is later incorporated into SQL commands, allowing an attacker to probe or extract data from the database without receiving immediate error messages. The consequence is the unauthorized disclosure of sensitive content such as user credentials, contact information, and internal application data, as well as the potential for further exploitation if additional logical weaknesses exist.

Affected Systems

This issue affects installations of the Groundhogg plugin for WordPress that are at or below version 4.8.3. Any site using those versions is subject to the risk, while the update to 4.9 or newer eliminates the vulnerability.

Risk and Exploitability

With a CVSS score of 7.6 the vulnerability is considered high severity. The EPSS score is not available, indicating that no publicly available exploitation data has been reported yet, and the vulnerability is not currently listed in CISA KEV. Assuming the plugin is exposed to externally accessible forms or URLs, an attacker could perform a blind injection attack by sending carefully crafted queries and interpreting response timing or boolean outcomes to extract data. No additional system compromises are required beyond the initial attempt to read database content.

Generated by OpenCVE AI on October 5, 2026 at 10:39 UTC.

Remediation

Vendor Solution

Update the WordPress Groundhogg plugin to the latest available version (at least 4.9).


OpenCVE Recommended Actions

  • Update the Groundhogg plugin to version 4.9 or newer, replacing the vulnerable install.
  • Remove or disable any legacy database tables that could have been altered by the injection, and clean any records that may contain malicious payloads.
  • If custom code interacts directly with Groundhogg data, audit and sanitize all user input before incorporating it into SQL statements to prevent recurrence of similar flaws.

Generated by OpenCVE AI on October 5, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.
Title WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T14:55:01.062Z

Reserved: 2026-10-02T00:22:13.106Z

Link: CVE-2026-104408

cve-icon Vulnrichment

Updated: 2026-10-05T14:50:26.452Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:08.623

Modified: 2026-10-05T15:17:14.890

Link: CVE-2026-104408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')