PT-2026-109502 · Trainingbusinesspros · Groundhogg — Crm

·

CVE-2026-104725

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the user parameter within the process edit() function, which allows any authenticated user with the edit contacts capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the edit users or promote users capabilities. This makes it possible for authenticated attackers, with sales rep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the {auto login link} replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the view notes and add notes capabilities that the sales rep role holds by default.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104725

Affected Products

Groundhogg — Crm