CVE-2026-11454: Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference

Published Aug 5, 2026
·
Updated

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The endpoint's permission callback checks only the role-level viewcontacts capability and readsingle() returns the full contact record by sequential integer ID without the object-level viewcontact ownership check applied elsewhere in the codebase. This makes it possible for authenticated attackers holding viewcontacts but not viewotherscontacts — notably Groundhogg's built-in Sales Rep role, designed to see only its own contacts — to read any contact record on the site, including PII, contact meta, owner IDs, the admin edit URL, and (for contacts linked to a WordPress user) that user's full capability set.

Affected Software

1 affected component
Groundhogg Groundhogg — CRM, Newsletters, and Marketing Automation (WordPress plugin)<=4.5.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Groundhogg — CRM, Newsletters, and Marketing Automation to a version that resolves this vulnerability.

    Fixed in 4.5.2
  2. Compensating control

    Mitigate the Insecure Direct Object Reference on GET /wp-json/gh/v4/contacts/<id> by restricting access to the REST endpoint so that users who have only view_contacts (e.g., Sales Rep) cannot view other contacts; ensure an object-level view_contact ownership check (ownership or equivalent) is enforced for each requested contact ID.

Event History

Aug 5, 2026
CVE Published
via MITRE·06:37 AM
Data Sourced
via MITRE·06:37 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203