Executive brief
Groundhogg is a WordPress plugin that provides CRM, email marketing, and marketing automation features. The plugin fails to validate redirect URLs in its email preference confirmation flow, allowing attackers to craft malicious links that redirect users to attacker-controlled websites. Unauthenticated users can be tricked into clicking links from the legitimate site that seamlessly redirect to phishing pages or malware sites, potentially compromising sensitive data or credentials.
Technical details
The vulnerability is an open redirect (CWE-601) in the email preference confirmation flow. The plugin does not restrict the redirect_to parameter to the site's own host, allowing unauthenticated attackers to specify arbitrary external URLs. The attack requires either a valid contact record on the site (obtained by subscribing through any opt-in form) or relies on a logged-in WordPress user with a Groundhogg contact record. Attackers craft a malicious link using legitimate pk and gi parameters along with an attacker-controlled redirect_to value, causing a 302 redirect to the specified external domain. The vulnerability was fixed in version 4.7.2.
Affected products
- Groundhogg Groundhogg before 4.7.2
Timeline
- 2026-09-07: disclosed
- 2026-09-09: patched: Fixed in version 4.7.2