PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92975 trainingbusinesspros CVE debrief

CVE-2026-92975 Groundhogg plugin for WordPress vulnerability allows unauthenticated privilege escalation to support user identity confusion. The plugin is vulnerable due to the `create_support_user()` function identifying support accounts solely by matching against publicly hardcoded constants. This makes it possible for an attacker to silently promote an account to administrator or super admin on multisite, resulting in full site takeover.

Vendor
trainingbusinesspros
Product
Groundhogg — CRM, Newsletters, and Marketing Automation
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress site administrators, security teams, and users of the Groundhogg plugin should assess exposure and apply patches to prevent exploitation. Additionally, they should monitor for suspicious activity and review system logs for potential security incidents. Site owners and security personnel must prioritize patching and verifying configuration to mitigate potential risks.

Why it matters

CVE-2026-92975 Groundhogg plugin vulnerability allows unauthenticated privilege escalation, enabling attackers to gain administrator or super admin access, potentially leading to full site takeover. WordPress site administrators and security teams should assess exposure and apply patches.

  • Full site takeover possible through exploitation
  • Elevation of privileges for an attacker
  • Potential for super admin access on multisite installations
  • Verification of patch application required

Technical summary

The Groundhogg plugin for WordPress is vulnerable to unauthenticated privilege escalation due to the `create_support_user()` function. This function identifies support accounts by matching against publicly hardcoded constants, allowing an attacker to promote an account to administrator or super admin on multisite. The vulnerability exists in Groundhogg plugin versions up to and including 4.8.3. Exploitation requires a two-actor flow: an attacker must first obtain or pre-plant an account with hardcoded credentials, after which a legitimate administrator must perform an action. This could lead to full site takeover if not properly addressed.

Defensive priority

High priority for WordPress site administrators and security teams to assess exposure and apply patches.

Recommended defensive actions

  • Assess exposure by checking if the Groundhogg plugin version is 4.8.3 or earlier.
  • Apply patches or updates to the Groundhogg plugin to prevent exploitation.
  • Monitor for suspicious account activity, especially related to support user identities.
  • Restrict user registration and account creation to prevent exploitation preconditions.
  • Verify patch application and ensure proper configuration.
  • Review system logs for potential security incidents.
  • Implement additional security measures to detect and prevent similar vulnerabilities.

Evidence notes

The vulnerability exists in Groundhogg plugin versions up to and including 4.8.3. The `create_support_user()` function is vulnerable due to its implementation. Exploitation requires a two-actor flow: an attacker must first obtain or pre-plant an account with hardcoded credentials, after which a legitimate administrator must perform an action.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92975 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92975

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92975 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92975

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.