Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.
Published: 2026-07-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper limitation of a pathname to a restricted directory, allowing an attacker to traverse directories and delete arbitrary files. The flaw can be used to remove files from the web server, destroying critical data, disrupting service, and potentially exposing sensitive information. The associated weakness is Path Traversal (CWE‑22).

Affected Systems

Vendor Adrian Tobey’s Groundhogg WordPress plugin is affected, from its initial release through version 4.4.1. Any site running the plugin on or before that version is potentially vulnerable.

Risk and Exploitability

With a CVSS score of 8.6, the defect represents high severity and the EPSS score indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, file deletion.

Generated by OpenCVE AI on July 31, 2026 at 12:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Groundhogg plugin to a version newer than 4.4.1, applying the vendor’s official release or patch.
  • If an immediate upgrade is not possible, temporarily disable the plugin or block its file‑deletion endpoint to prevent exploitation.
  • Configure server‑side path validation or deny unknown file‑system traversal attempts by updating web‑application firewall rules and monitoring access logs for suspicious directory‑traversal patterns.

Generated by OpenCVE AI on July 31, 2026 at 12:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Adrian Tobey
Adrian Tobey groundhogg
Wordpress
Wordpress wordpress
Vendors & Products Adrian Tobey
Adrian Tobey groundhogg
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.
Title WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Adrian Tobey Groundhogg
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:53.542Z

Reserved: 2026-06-24T12:46:01.633Z

Link: CVE-2026-57389

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')