Description
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
Published: 2026-09-09
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Patch
AI Analysis

Impact

The Groundhogg WordPress plugin prior to version 4.7.2 allows an attacker to supply an arbitrary redirect_to URL in the email preference confirmation flow that is not constrained to the site’s own domain. This unsanitized redirect can lead to open redirect exploitation, which may be leveraged for phishing, malware delivery or loss of user trust. The weakness originates from inadequate host validation, resulting in a classic open redirect (CWE-601).

Affected Systems

Sites running the Groundhogg CRM, Newsletters and Marketing Automation plugin on WordPress with a plugin version earlier than 4.7.2 are impacted. The plugin is distributed as a WordPress plugin and can be installed on any WordPress installation that has not applied the security update.

Risk and Exploitability

The flaw is exploitable without authentication; a crafted link can be embedded in email, social media or other public channels and will redirect unsuspecting visitors to a malicious site. The CVSS score of 4.7 indicates medium severity, while the EPSS score of < 1% suggests a low probability of exploitation. Although not listed in the CISA KEV catalog, its ease of exploitation and potential for social engineering give it a moderate risk rating. The likely attack vector is an unsolicited link sent to users of the affected WordPress site.

Generated by OpenCVE AI on September 9, 2026 at 18:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Groundhogg plugin to version 4.7.2 or newer.
  • If an immediate update is not feasible, enforce host checks on the redirect_to parameter in any custom or third‑party code to accept only same‑site URLs.
  • As a temporary measure, block or whitelist external redirects at the web‑application or server level to prevent unintended redirects from the email preference confirmation flow.

Generated by OpenCVE AI on September 9, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
Title Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:38:38.352Z

Reserved: 2026-08-27T11:49:03.085Z

Link: CVE-2026-81741

cve-icon Vulnrichment

Updated: 2026-09-09T15:33:03.034Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:17.157

Modified: 2026-09-09T16:17:10.747

Link: CVE-2026-81741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T19:00:15Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')