Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92975— Groundhogg <= 4.8.3 - Unauthenticated Privilege Escalation to Support User Identity Confusion

Quick assessment

Affected
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Groundhogg — CRM、通讯簿和营销自动化工具存在权限提升漏洞。该漏洞影响所有版本,包括最高版本 4.8.3,漏洞位于 函数中。 该漏洞的成因在于:该函数仅通过匹配公开硬编码常量来识别支持账户,这些常量包括用户登录名 以及邮箱地址 和 。然而,在第 238 行使用的 邮箱平等性检查并不构成安全边界,因为用户完全能够控制自己的邮箱值。 这使得攻击者可以通过构造一个用户登录名为 且用户邮箱匹配上述硬编码支持邮箱之一的账户,静默地将该账户提升为管理员权限。此外,在多站点(Multisi

CVSS 8.1 · High EPSS 0.35% · P27

Affected Version Matrix 1

VendorProduct Version RangeStatus
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation ≤ 4.8.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92975

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Groundhogg <= 4.8.3 - Unauthenticated Privilege Escalation to Support User Identity Confusion
Source: CVE Program / CVE List V5
Vulnerability Description
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.3 via the `create_support_user()` function. This is due to the function identifying the support account solely by matching against publicly hardcoded constants — `user_login` `'groundhogg'` and email addresses `'support@groundhogg.io'` / `'help@groundhogg.io'` — where the `in_array()` email-equality check at line 238 is not a security boundary because any user fully controls their own email value. This makes it possible for an attacker with an account whose `user_login` is `'groundhogg'` and whose `user_email` matches one of the hardcoded support constants to have that account silently promoted to administrator — and additionally to super admin on multisite when the triggering administrator holds `manage_network_options` — resulting in full site takeover. Exploitation requires a two-actor flow: the attacker must first obtain or pre-plant an account with the hardcoded credentials (possible when open user registration is enabled or another account-creation path exists), after which a legitimate administrator must invoke the support-access feature via the `submit_ticket` or `process_send_support_access` entry points to trigger the promotion.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation 0 ~ 4.8.3 -

II. Public POCs for CVE-2026-92975

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92975

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-92975 (3)

Vendor Advisories for CVE-2026-92975 (1)

Other References for CVE-2026-92975 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92975

No comments yet


Leave a comment