CVE-2026-97644

Published: Ott 03, 2026 Last Modified: Ott 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0050
Percentile
0,4th
Updated

Single Data Point

Only one EPSS measurement is available for this CVE. Trend analysis requires multiple data points over time.

269

Improper Privilege Management

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.3/api/v3/contact…
https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.3/api/v4/emails-…
https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.3/db/contacts.ph…
https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.3/includes/main-…
https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.3/includes/repla…
https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.3/includes/rewri…
https://plugins.trac.wordpress.org/changeset/3724910/groundhogg/trunk/api/v3/co…
https://plugins.trac.wordpress.org/changeset?reponame=&new=3724910%40groundhogg…
https://www.wordfence.com/threat-intel/vulnerabilities/id/557306b7-7b66-465e-8d…