PatchSiren cyber security CVE debrief
CVE-2026-92975 trainingbusinesspros CVE debrief
CVE-2026-92975 Groundhogg plugin for WordPress vulnerability allows unauthenticated privilege escalation to support user identity confusion. The plugin is vulnerable due to the `create_support_user()` function identifying support accounts solely by matching against publicly hardcoded constants. This makes it possible for an attacker to silently promote an account to administrator or super admin on multisite, resulting in full site takeover.
- Vendor
- trainingbusinesspros
- Product
- Groundhogg — CRM, Newsletters, and Marketing Automation
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress site administrators, security teams, and users of the Groundhogg plugin should assess exposure and apply patches to prevent exploitation. Additionally, they should monitor for suspicious activity and review system logs for potential security incidents. Site owners and security personnel must prioritize patching and verifying configuration to mitigate potential risks.
Why it matters
CVE-2026-92975 Groundhogg plugin vulnerability allows unauthenticated privilege escalation, enabling attackers to gain administrator or super admin access, potentially leading to full site takeover. WordPress site administrators and security teams should assess exposure and apply patches.
- Full site takeover possible through exploitation
- Elevation of privileges for an attacker
- Potential for super admin access on multisite installations
- Verification of patch application required
Technical summary
The Groundhogg plugin for WordPress is vulnerable to unauthenticated privilege escalation due to the `create_support_user()` function. This function identifies support accounts by matching against publicly hardcoded constants, allowing an attacker to promote an account to administrator or super admin on multisite. The vulnerability exists in Groundhogg plugin versions up to and including 4.8.3. Exploitation requires a two-actor flow: an attacker must first obtain or pre-plant an account with hardcoded credentials, after which a legitimate administrator must perform an action. This could lead to full site takeover if not properly addressed.
Defensive priority
High priority for WordPress site administrators and security teams to assess exposure and apply patches.
Recommended defensive actions
- Assess exposure by checking if the Groundhogg plugin version is 4.8.3 or earlier.
- Apply patches or updates to the Groundhogg plugin to prevent exploitation.
- Monitor for suspicious account activity, especially related to support user identities.
- Restrict user registration and account creation to prevent exploitation preconditions.
- Verify patch application and ensure proper configuration.
- Review system logs for potential security incidents.
- Implement additional security measures to detect and prevent similar vulnerabilities.
Evidence notes
The vulnerability exists in Groundhogg plugin versions up to and including 4.8.3. The `create_support_user()` function is vulnerable due to its implementation. Exploitation requires a two-actor flow: an attacker must first obtain or pre-plant an account with hardcoded credentials, after which a legitimate administrator must perform an action.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Groundhogg <= 4.8.3 - Unauthenticated Privilege Escalation to Support User Identity Confusion
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/92xxx/CVE-2026-92975.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.1/admin/help/help-page.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/groundhoggwp/groundhogg/commit/4b413aa6e
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.