CVE-2026-104725: Groundhogg <= 4.9 - Authenticated (Custom+) Privilege Escalation to 'user' Parameter
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the user parameter within the processedit() function, which allows any authenticated user with the editcontacts capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the editusers or promoteusers capabilities. This makes it possible for authenticated attackers, with salesrep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the {autologinlink} replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the viewnotes and addnotes capabilities that the salesrep role holds by default.
Affected Software
Event History
Frequently Asked Questions
Which users can realistically exploit this issue?
Any authenticated user with the Groundhogg edit_contacts capability can exploit it. The sales_rep role has the required capabilities by default, including the note permissions needed to retrieve the generated auto-login URL.
Does exploitation require an existing administrator account to be compromised first?
No. An attacker can link a contact record to an arbitrary existing WordPress account, including an administrator account, without needing edit_users or promote_users capabilities.
What does an attacker need to do to obtain administrator access?
They must reassign a contact's linked WordPress user ID to an administrator, create a note containing the {auto_login_link} replacement tag, read the generated URL from the note, and visit it to authenticate as that administrator.
Are default Groundhogg sales representatives affected?
Yes. The sales_rep role holds edit_contacts, view_notes, and add_notes by default, which are sufficient for the described privilege-escalation path.