Refine your search
1 vulnerability found for Groundhogg — CRM, Newsletters, and Marketing Automation by Unknown
CVE-2026-81660 (GCVE-0-2026-81660)
Vulnerability from cvelistv5
Published
2026-08-30 06:00
Modified
2026-08-30 06:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.
References
| URL | Tags | ||||
|---|---|---|---|---|---|
|
|||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Unknown | Groundhogg — CRM, Newsletters, and Marketing Automation |
Version: 0 ≤ |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Groundhogg \u2014 CRM, Newsletters, and Marketing Automation",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.5.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Artus KG"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-79 Cross-Site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-30T06:00:18.805Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/cfdb4107-6010-4c29-baf3-3111765f48c2/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Groundhogg \u003c 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-81660",
"datePublished": "2026-08-30T06:00:18.805Z",
"dateReserved": "2026-08-27T10:06:26.911Z",
"dateUpdated": "2026-08-30T06:00:18.805Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}