CVE-2026-97644: Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the createcontact function in the v3 REST endpoint (POST /gh/v3/contacts) is gated solely by the addcontacts capability and forwards the full request payload — including the security-bearing userid column — into the upsert path of ContactsDB::add(), which bypasses the ownership guard that ContactsDB::update() enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (POST /gh/v4/emails/test) — also accessible to the Sales Representative role via the sendemails capability — to generate an {autologinurl} one-time permissions key bound to the rebound contact, and consume that link to call wpsetauthcookie() and gain a fully authenticated session as the WordPress Administrator.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Groundhogg user with Sales Representative-level access or higher can exploit it. The required capabilities are add_contacts for the v3 contact endpoint and send_emails for the v4 email-test endpoint.
Does exploitation require administrator interaction or a separate administrator credential?
No. The attack has no user-interaction requirement and does not require the attacker to know an administrator password; it abuses an existing administrator WordPress user ID to obtain an authenticated administrator session.
What access does a successful attacker gain?
A successful attacker can obtain a fully authenticated WordPress Administrator session. This enables high-impact compromise of confidentiality, integrity, and availability.
Which component paths are involved in the attack chain?
The chain uses POST /gh/v3/contacts to rebind a contact record through the user_id parameter, followed by POST /gh/v4/emails/test to generate an auto-login URL for that rebound contact.
Are affected versions identified?
All Groundhogg versions up to and including 4.9 are affected according to the provided data.