Junglewise Threat Intelligence

CVE-2026-40727: Groundhogg arbitrary file deletion in Sales Representative component

CVE-2026-40727 · Severity: high · CVSS 7.7 · Published 2026-06-15

Technologies: Groundhogg. Vendors: Groundhogg.

Executive brief

Groundhogg is a marketing automation and CRM plugin for WordPress. A security flaw allows users with 'Sales Representative' permissions to delete arbitrary files from the web server. This could lead to a complete site failure or service outage if critical system files are removed.

Technical details

The Groundhogg plugin for WordPress (versions 4.4 and below) contains a path traversal vulnerability (CWE-22) that allows for arbitrary file deletion. The flaw is accessible to authenticated users with the 'Sales Representative' role. By exploiting this, an attacker can send a crafted request to delete sensitive files on the server, including WordPress core files or configuration files. This vulnerability is rated with a CVSS score of 7.7, primarily impacting system availability. A patch is available in version 4.4.1.

Affected products

  • Groundhogg Groundhogg <= 4.4

Timeline

  • 2026-01-06: other: Reported by researcher daroo
  • 2026-04-16: patched: Patch released in version 4.4.1
  • 2026-06-15: disclosed: CVE published and NVD entry created

References

Related threats