Groundhogg — CRM, Newsletters, and Marketing Automation

Information

Software Type Plugin
Software Slug groundhogg (view on wordpress.org)
Software Status Active
Software Author trainingbusinesspros
Software Website groundhogg.io
Software Downloads 332,250
Software Active Installs 2,000
Software Record Last Updated August 12, 2026

Showing 1-20 of 32 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference Patched CVE-2026-11454 6.5 Lucius-log August 4, 2026
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.4.1 - Authenticated (Sales Representative+) Arbitrary File Deletion Patched CVE-2026-57389 8.1 she11f July 8, 2026
Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter Patched CVE-2026-14029 6.5 Wordfence PRISM July 1, 2026
Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter Patched CVE-2026-13333 6.5 Chloe Chamberland, Wordfence PRISM June 26, 2026
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5 - Authenticated (Sales representative+) SQL Injection Patched CVE-2026-57667 6.5 Jonathan Dersch June 26, 2026
Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter Patched CVE-2026-13331 6.5 Wordfence PRISM, Chloe Chamberland June 26, 2026
Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter Patched CVE-2026-13226 6.5 Wordfence PRISM June 25, 2026
Groundhogg — CRM, Newsletters, and Marketing Automation < 4.4.1 - Missing Authorization Patched CVE-2026-40793 4.3 Jakub Herman April 24, 2026
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.4 - Authenticated (Sales Representative+) Arbitrary File Deletion Patched CVE-2026-40727 8.1 daroo April 16, 2026
Groundhogg <= 4.2.6.1 - Authenticated (Admin+) SQL Injection Patched CVE-2025-12750 4.9 NAKLEH ZEIDAN November 20, 2025
Groundhogg <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-64367 6.4 zaim October 31, 2025
Groundhogg <= 4.2.2 - Authenticated (Sales Representative+) PHP Object Injection Patched CVE-2025-54053 7.5 63n0 August 5, 2025
Groundhogg <= 4.2.1 - Authenticated (Sales Rep+) Arbitrary File Upload Patched CVE-2025-48300 8.8 Gai Tanaka (63n0) July 4, 2025
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion Patched CVE-2025-4206 7.2 Phat Do May 8, 2025
Groundhogg <= 3.7.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter Patched CVE-2025-1267 5.5 Cristian Bejan (cbejan) March 31, 2025
Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function Patched CVE-2025-0394 8.8 wesley (wcraft) January 13, 2025
Groundhogg <= 3.7.3.3 - Reflected Cross-Site Scripting Patched CVE-2024-56289 6.1 Webula January 3, 2025
Groundhogg <= 3.4.2.3 - Reflected Cross-Site Scripting Patched CVE-2024-37264 6.1 Ananda Dhakal June 27, 2024
Groundhogg <= 3.4.2.3 - Cross-Site Request Forgery Patched CVE-2024-37235 4.3 Ananda Dhakal June 21, 2024
Groundhogg <= 2.7.11.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via Task Data Patched CVE-2023-40681 4.4 Hamoud Al Helmani October 25, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation