Junglewise Threat Intelligence

CVE-2026-57389: Adrian Tobey Groundhogg path traversal arbitrary file deletion

CVE-2026-57389 · Severity: high · CVSS 8.6 · Published 2026-07-13

Technologies: Groundhogg. Vendors: Groundhogg.

Executive brief

Groundhogg is a marketing automation and CRM plugin for WordPress. A security flaw in this plugin allows an attacker to delete critical files from the website's server. This can lead to a complete service outage, website defacement, or the removal of security configurations, potentially breaking the site's functionality and impacting business operations.

Technical details

A path traversal vulnerability (CWE-22) exists in the Groundhogg plugin for WordPress through version 4.4.1. The flaw allows an unauthenticated remote attacker to bypass directory restrictions and delete arbitrary files on the server. By manipulating file path inputs, an attacker can target critical system or application files, leading to a complete denial of service (DoS) as the website or server may cease to function. The vulnerability is addressed in version 4.5.

Affected products

  • Adrian Tobey Groundhogg <= 4.4.1

Timeline

  • 2026-05-25: other: Reported by she11f
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: NVD publication date

References

Related threats