PT-2026-83527 · WordPress · Groundhogg
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin versions prior to 4.5.13
Description
Insufficient validation and escaping of values submitted to optional web form fields allow unauthenticated users to execute Stored Cross-Site Scripting (XSS) attacks. This occurs when the submitted data is stored and subsequently displayed within an administrative area, targeting users with high privileges.
Recommendations
Update the plugin to version 4.5.13 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Groundhogg