Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104725— Groundhogg <= 4.9 - Authenticated (Custom+) Privilege Escalation to 'user' Parameter

Quick assessment

Affected
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Groundhogg——CRM、新闻通讯与营销自动化工具——在所有版本(最高至 4.9 版)中存在权限提升漏洞。该漏洞源于 函数中对 参数缺乏所有权验证和权限检查,导致任何具备 能力的已认证用户,无需拥有 或 权限,即可将联系人的关联 WordPress 用户 ID 随意更改为任意账户。 这使得具备销售代表(sales_rep)或更高级别权限的已认证攻击者能够通过以下方式提升权限至管理员:首先,将联系人链接到管理员的 WordPress 用户 ID;其次,创建一条包含 替换标签的备注,以触

CVSS 8.8 · High EPSS 0.33% · P25

Possible ATT&CK Techniques 1 AI

T1078.004 · Cloud Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation ≤ 4.9 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104725

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Groundhogg <= 4.9 - Authenticated (Custom+) Privilege Escalation to 'user' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_users` or `promote_users` capabilities. This makes it possible for authenticated attackers, with sales_rep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the `{auto_login_link}` replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the `view_notes` and `add_notes` capabilities that the sales_rep role holds by default.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation 0 ~ 4.9 -

II. Public POCs for CVE-2026-104725

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104725

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104725 (2)

Vendor Advisories for CVE-2026-104725 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104725

No comments yet


Leave a comment