Executive brief
Groundhogg is a marketing automation and CRM plugin for WordPress. A security flaw allows users with 'Sales Representative' permissions to delete arbitrary files from the web server. This could lead to a complete site failure or service outage if critical system files are removed.
Technical details
The Groundhogg plugin for WordPress (versions 4.4 and below) contains a path traversal vulnerability (CWE-22) that allows for arbitrary file deletion. The flaw is accessible to authenticated users with the 'Sales Representative' role. By exploiting this, an attacker can send a crafted request to delete sensitive files on the server, including WordPress core files or configuration files. This vulnerability is rated with a CVSS score of 7.7, primarily impacting system availability. A patch is available in version 4.4.1.
Affected products
- Groundhogg Groundhogg <= 4.4
Timeline
- 2026-01-06: other: Reported by researcher daroo
- 2026-04-16: patched: Patch released in version 4.4.1
- 2026-06-15: disclosed: CVE published and NVD entry created