Junglewise Threat Intelligence

CVE-2026-40793: Groundhogg plugin broken access control in WordPress

CVE-2026-40793 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: Groundhogg. Vendors: Groundhogg.

Executive brief

Groundhogg is a marketing automation and CRM plugin for WordPress. A security flaw in versions prior to 4.4.1 allows users with basic 'Subscriber' accounts to bypass security restrictions and perform actions they should not be authorized to do. This could allow low-level users to modify settings or data, potentially disrupting marketing operations or compromising site integrity.

Technical details

A broken access control vulnerability exists in the Groundhogg plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an authenticated attacker with Subscriber-level privileges to execute functions or actions that should be restricted to higher-privileged users. The vulnerability is reachable over the network without user interaction, though it does require a valid low-level account. Successful exploitation allows the attacker to modify data or configurations (Integrity: High) but does not directly lead to data exfiltration or service downtime. The issue is resolved in version 4.4.1.

Affected products

  • Groundhogg Groundhogg < 4.4.1

Timeline

  • 2026-03-25: other: Reported by Jakub Herman
  • 2026-04-24: advisory: Initial disclosure by Patchstack
  • 2026-04-24: patched: Patch available in version 4.4.1
  • 2026-06-15: disclosed: NVD publication date

References

Related threats