CVE-2026-104408: WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Groundhogg pluginto a version that resolves this vulnerability.Fixed in 4.9
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low attack complexity, and does not require user interaction. However, the attacker must already hold high privileges.
What is the expected impact if exploitation succeeds?
The reported impact includes high confidentiality impact and low availability impact. No integrity impact is indicated in the CVSS vector.
Which Groundhogg versions are identified as affected?
The issue is reported to affect Groundhogg versions through 4.8.3. The earliest affected version is not specified.