Executive brief
Groundhogg is a WordPress plugin used for customer relationship management (CRM) and marketing automation. A security flaw in the plugin allows logged-in users to perform unauthorized database queries. This could lead to the theft of sensitive customer information and business data stored within the WordPress database.
Technical details
The Groundhogg plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping and lack of preparation on SQL queries involving the 'after' parameter. The vulnerability is accessible via the 'wp_ajax_groundhogg_get_contacts_table' AJAX handler, which lacks proper nonce verification and has its capability checks commented out. While the intended access level is Sales Manager or higher, the lack of authorization checks allows any authenticated user to exploit the flaw. Attackers can append malicious SQL commands to existing queries to extract sensitive data from the database. The issue is present in all versions up to and including 4.5.4.
Affected products
- trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.4
Timeline
- 2026-06-26: disclosed: Initial NVD publication date
References
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.4/admin/contacts/contacts-page.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.4/admin/contacts/tables/contacts-table.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.4/includes/contact-query.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.4/includes/functions.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.4/includes/legacy-contact-query.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.4/includes/legacy-contact-query.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3585561%40groundhogg&new=3585561%40groundhogg&sfp_email=&sfph_mail=