Junglewise Threat Intelligence

CVE-2026-85310: Groundhogg import_contacts path traversal

CVE-2026-85310 · Severity: medium · CVSS 6.5 · Published 2026-09-10

Technologies: Groundhogg. Vendors: Groundhogg.

Executive brief

Groundhogg is a popular WordPress plugin for contact and customer relationship management. A path traversal vulnerability in the import_contacts function allows attackers to access files outside the website's intended directory, potentially exposing sensitive server configuration files or database credentials stored elsewhere on the server.

Technical details

A path traversal vulnerability exists in the import_contacts function of Groundhogg plugin versions 4.7.1 and earlier. The vulnerability allows an attacker with appropriate privileges to use directory traversal sequences (e.g., "../") to escape the website's folder and access arbitrary files on the server. The vulnerability is classified as broken access control and requires the import_contacts privilege to exploit. The attack is network-accessible and does not require user interaction. Version 4.7.2 and later contain the fix.

Affected products

  • Groundhogg Groundhogg <=4.7.1

Timeline

  • 2026-09-09: disclosed: Vulnerability disclosed and published
  • 2026-09-09: patched: Fix released in version 4.7.2

References

Related threats