Description
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.
Published: 2026-10-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation leading to Administrator takeover
Action: Immediate Patch
AI Analysis

Impact

The Groundhogg plugin allows an authenticated user with the Sales Representative capability or higher to rebind any contact record to an arbitrary WordPress user ID by posting to the v3 contacts endpoint. The create_contact function forwards the full request payload, including the user_id field, to the database upsert routine, skipping the ownership guard that normally prevents changing a contact’s owner. By rebinding a contact to an Administrator’s user ID, the attacker can then call the v4 email-test endpoint, which generates an auto‑login URL bound to the rebound contact and is accessible to the same role. Consuming that link invokes wp_set_auth_cookie() and delivers a fully authenticated Administrator session. This chain of API calls therefore results in a complete takeover of the Word site.

Affected Systems

Affected systems are WordPress installations that have the Groundhogg plugin version 4.9 or earlier. The vulnerability exists in all versions up to and including 4.9. The plugin is provided by trainingbusinesspros and is commonly used for CRM, newsletters and marketing automation within WordPress sites.

Risk and Exploitability

Risk and exploitability: The CVSS score of 8.8 indicates a high severity. EPSS is not available, so the global exploitation probability is unknown, but the flaw is not listed in CISA’s KEV catalog. The exploit requires an authenticated user with the Sales Representative role or higher, which is a common role in marketing teams. Once the user has that role, the two API calls are publicly documented and can be executed over HTTPS, making the vulnerability readily exploitable by an attacker who can gain access to a legitimate user account with sufficient privileges.

Generated by OpenCVE AI on October 3, 2026 at 04:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Groundhogg to the latest version (4.9.1 or later), which contains the fix for the Contact Identity Rebinding flaw.
  • Revoke the add_contacts and send_emails capabilities from all non‑administrator roles so that neither endpoint can be used by Sales Representatives.
  • Audit your user base to ensure that only trusted users are granted the Sales Representative role; downgrade or remove the role from users who do not require these capabilities.
  • If the email‑test endpoint is not essential, block or disable POST /gh/v4/emails/test for non‑administrators via firewall or role restrictions.

Generated by OpenCVE AI on October 3, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.
Title Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:46.419Z

Reserved: 2026-09-24T18:20:11.240Z

Link: CVE-2026-97644

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:38.761Z

cve-icon NVD

Status : Received

Published: 2026-10-03T04:18:04.917

Modified: 2026-10-03T16:16:49.700

Link: CVE-2026-97644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T05:00:14Z

Weaknesses
  • CWE-269

    Improper Privilege Management