Executive brief
Groundhogg is a WordPress plugin used for managing customer relationships, email newsletters, and marketing automation. A security flaw in the plugin's search feature allows authorized users with 'marketer' level access or higher to perform unauthorized database queries. This could lead to the exposure of sensitive customer data and internal business information stored in the website's database.
Technical details
The Groundhogg plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions up to and including 4.5.5. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper SQL query preparation in several components, including the base-object-api and database handling scripts. An authenticated attacker with 'marketer' level privileges or higher can exploit this by injecting malicious SQL commands into existing queries. This allows for the extraction of sensitive data from the WordPress database. The issue is addressed in subsequent updates via improved input sanitization and the use of prepared statements.
Affected products
- trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation up to, and including, 4.5.5
Timeline
- 2026-06-27: disclosed
References
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.5/api/v4/base-object-api.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.5/db/db.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.5/db/db.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.5/db/steps.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.5/db/steps.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3586389%40groundhogg&new=3586389%40groundhogg&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/20ee6bc7-2732-4da3-b005-a971d12b0e32?source=cve