Impact
The Groundhogg plugin allows an authenticated user with the Sales Representative capability or higher to rebind any contact record to an arbitrary WordPress user ID by posting to the v3 contacts endpoint. The create_contact function forwards the full request payload, including the user_id field, to the database upsert routine, skipping the ownership guard that normally prevents changing a contact’s owner. By rebinding a contact to an Administrator’s user ID, the attacker can then call the v4 email-test endpoint, which generates an auto‑login URL bound to the rebound contact and is accessible to the same role. Consuming that link invokes wp_set_auth_cookie() and delivers a fully authenticated Administrator session. This chain of API calls therefore results in a complete takeover of the Word site.
Affected Systems
Affected systems are WordPress installations that have the Groundhogg plugin version 4.9 or earlier. The vulnerability exists in all versions up to and including 4.9. The plugin is provided by trainingbusinesspros and is commonly used for CRM, newsletters and marketing automation within WordPress sites.
Risk and Exploitability
Risk and exploitability: The CVSS score of 8.8 indicates a high severity. EPSS is not available, so the global exploitation probability is unknown, but the flaw is not listed in CISA’s KEV catalog. The exploit requires an authenticated user with the Sales Representative role or higher, which is a common role in marketing teams. Once the user has that role, the two API calls are publicly documented and can be executed over HTTPS, making the vulnerability readily exploitable by an attacker who can gain access to a legitimate user account with sufficient privileges.
OpenCVE Enrichment