CVE-2026-40727: WordPress Groundhogg plugin <= 4.4 - Arbitrary File Deletion vulnerability
Published Jun 15, 2026
·Updated
Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
Affected Software
1 affected component
Groundhogg Groundhogg<=4.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/groundhoggto a version that resolves this vulnerability.Fixed in 4.4.1
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40727?
The severity of CVE-2026-40727 is rated high with a score of 7.7.
2
What type of vulnerability is CVE-2026-40727?
CVE-2026-40727 is an arbitrary file deletion vulnerability affecting the Groundhogg plugin.
3
How do I fix CVE-2026-40727?
To fix CVE-2026-40727, update the Groundhogg plugin to version 4.4.1 or later.
4
What are the potential impacts of CVE-2026-40727?
CVE-2026-40727 could allow unauthorized users to delete critical files from the server.
5
Which versions of the Groundhogg plugin are affected by CVE-2026-40727?
CVE-2026-40727 affects all versions of the Groundhogg plugin prior to version 4.4.1.