PatchSiren

trainingbusinesspros CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM trainingbusinesspros CVE published 2026-08-05

CVE-2026-11454

The Groundhogg plugin for WordPress has a vulnerability allowing authenticated attackers with view_contacts capability to read any contact record, including PII and other sensitive information, due to an insecure direct object reference in the /wp-json/gh/v4/contacts/<id> REST endpoint. This vulnerability affects all versions up to, and including, 4.5.2 of the plugin. The endpoint's permission callback ch [truncated]

MEDIUM trainingbusinesspros CVE published 2026-06-27

CVE-2026-13331

The Groundhogg plugin for WordPress is vulnerable to SQL injection attacks via the 'search' parameter in versions up to and including 4.5.5. This issue arises from insufficient escaping of user-supplied parameters and inadequate preparation of existing SQL queries. Exploitation of this vulnerability allows authenticated attackers with marketer-level access or higher to append additional SQL queries to exi [truncated]