Executive brief
Groundhogg is a WordPress plugin used for managing customer relationships and marketing automation. A security flaw in the plugin allows certain authorized users to run unauthorized database commands. This could lead to the exposure of sensitive customer data and internal business information stored in the website's database.
Technical details
The Groundhogg plugin for WordPress is vulnerable to a generic SQL Injection via the 'select' parameter in versions up to and including 4.5.8. This issue stems from insufficient escaping of user-supplied input and a lack of proper SQL query preparation in components such as base-object-api.php and query.php. An authenticated attacker with 'custom-level' access or higher—specifically requiring the 'view_contacts' capability—can append malicious SQL queries to existing ones. This allows for the unauthorized extraction of sensitive data from the database. A patch has been released in subsequent versions to address the improper neutralization of special elements in SQL commands (CWE-89).
Affected products
- trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.8
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory
References
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/api/v4/base-object-api.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/db/db.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/db/query/query.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/db/query/query.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/api/v4/base-object-api.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/db/db.php
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/db/query/query.php