CVE-2026-85310: WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability
Published Sep 10, 2026
·Updated
importcontacts Path Traversal in Groundhogg <= 4.7.1 versions.
Affected Software
1 affected component
WordPress Groundhogg plugin<=4.7.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Groundhogg pluginto a version that resolves this vulnerability.Fixed in 4.7.2
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. It can be exploited remotely without user interaction, according to the CVSS vector.
2
What is the likely impact if exploitation succeeds?
The issue may expose confidential information through path traversal. The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact.