CVE-2026-104385: WordPress Groundhogg plugin <= 4.8.3 - Sensitive Data Exposure vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.
Affected Software
1 affected component
Groundhogg Groundhogg plugin<=4.8.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Groundhogg pluginto a version that resolves this vulnerability.Fixed in 4.9
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or user interaction to exploit this issue?
No. The vulnerability is described as unauthenticated, and the vector indicates it can be exploited remotely without privileges or user interaction.
2
How can I determine whether my site is affected?
A site is affected if it uses the Groundhogg WordPress plugin at version 4.8.3 or earlier.