Junglewise Threat Intelligence

CVE-2026-57667: Adrian Tobey Groundhogg SQL injection in Sales Representative component

CVE-2026-57667 · Severity: high · CVSS 8.5 · Published 2026-06-26

Technologies: Groundhogg. Vendors: Groundhogg.

Executive brief

Groundhogg is a marketing automation and CRM plugin for WordPress. A security vulnerability in versions 4.5 and earlier allows an attacker with Sales Representative privileges to execute unauthorized database commands. This could lead to the theft of sensitive customer data, exposure of site configuration, or disruption of the marketing platform's operations.

Technical details

A SQL injection vulnerability exists in the Groundhogg plugin for WordPress up to and including version 4.5. The flaw is located in components accessible to users with the 'Sales Representative' role, where input is improperly neutralized before being used in a SQL query (CWE-89). An authenticated attacker with low-level privileges can exploit this to interact directly with the database, potentially leading to sensitive information disclosure or limited impact on service availability. The issue is addressed in version 4.5.1.

Affected products

  • Adrian Tobey Groundhogg <= 4.5

Timeline

  • 2026-05-29: other: Reported by Baikuya
  • 2026-06-26: patched: Version 4.5.1 released to address the vulnerability
  • 2026-06-26: advisory: Published by Patchstack and NVD

References

Related threats