PT-2026-83527 · WordPress · Groundhogg

·

CVE-2026-81660

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin versions prior to 4.5.13
Description Insufficient validation and escaping of values submitted to optional web form fields allow unauthenticated users to execute Stored Cross-Site Scripting (XSS) attacks. This occurs when the submitted data is stored and subsequently displayed within an administrative area, targeting users with high privileges.
Recommendations Update the plugin to version 4.5.13 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81660

Affected Products

Groundhogg