CVE-2026-104725: Groundhogg <= 4.9 - Authenticated (Custom+) Privilege Escalation to 'user' Parameter

Published Oct 10, 2026
·
Updated

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the user parameter within the processedit() function, which allows any authenticated user with the editcontacts capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the editusers or promoteusers capabilities. This makes it possible for authenticated attackers, with salesrep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the {autologinlink} replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the viewnotes and addnotes capabilities that the salesrep role holds by default.

Affected Software

1 affected component
Groundhogg Groundhogg<=4.9

Event History

Oct 10, 2026
CVE Published
via MITRE·05:30 AM
Data Sourced
via MITRE·05:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can realistically exploit this issue?

Any authenticated user with the Groundhogg edit_contacts capability can exploit it. The sales_rep role has the required capabilities by default, including the note permissions needed to retrieve the generated auto-login URL.

2

Does exploitation require an existing administrator account to be compromised first?

No. An attacker can link a contact record to an arbitrary existing WordPress account, including an administrator account, without needing edit_users or promote_users capabilities.

3

What does an attacker need to do to obtain administrator access?

They must reassign a contact's linked WordPress user ID to an administrator, create a note containing the {auto_login_link} replacement tag, read the generated URL from the note, and visit it to authenticate as that administrator.

4

Are default Groundhogg sales representatives affected?

Yes. The sales_rep role holds edit_contacts, view_notes, and add_notes by default, which are sufficient for the described privilege-escalation path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203