The Groundhogg plugin for WordPress has a vulnerability allowing authenticated attackers with view_contacts capability to read any contact record, including PII and other sensitive information, due to an insecure direct object reference in the /wp-json/gh/v4/contacts/<id> REST endpoint. This vulnerability affects all versions up to, and including, 4.5.2 of the plugin. The endpoint's permission callback ch [truncated]
MEDIUMtrainingbusinessprosCVE published 2026-06-27
The Groundhogg plugin for WordPress is vulnerable to SQL injection attacks via the 'search' parameter in versions up to and including 4.5.5. This issue arises from insufficient escaping of user-supplied parameters and inadequate preparation of existing SQL queries. Exploitation of this vulnerability allows authenticated attackers with marketer-level access or higher to append additional SQL queries to exi [truncated]