CVE-2026-97644: Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test

Published Oct 3, 2026
·
Updated

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the createcontact function in the v3 REST endpoint (POST /gh/v3/contacts) is gated solely by the addcontacts capability and forwards the full request payload — including the security-bearing userid column — into the upsert path of ContactsDB::add(), which bypasses the ownership guard that ContactsDB::update() enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (POST /gh/v4/emails/test) — also accessible to the Sales Representative role via the sendemails capability — to generate an {autologinurl} one-time permissions key bound to the rebound contact, and consume that link to call wpsetauthcookie() and gain a fully authenticated session as the WordPress Administrator.

Affected Software

1 affected component
Groundhogg Groundhogg<=4.9

Event History

Oct 3, 2026
CVE Published
via MITRE·03:25 AM
Data Sourced
via MITRE·03:25 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Groundhogg user with Sales Representative-level access or higher can exploit it. The required capabilities are add_contacts for the v3 contact endpoint and send_emails for the v4 email-test endpoint.

2

Does exploitation require administrator interaction or a separate administrator credential?

No. The attack has no user-interaction requirement and does not require the attacker to know an administrator password; it abuses an existing administrator WordPress user ID to obtain an authenticated administrator session.

3

What access does a successful attacker gain?

A successful attacker can obtain a fully authenticated WordPress Administrator session. This enables high-impact compromise of confidentiality, integrity, and availability.

4

Which component paths are involved in the attack chain?

The chain uses POST /gh/v3/contacts to rebind a contact record through the user_id parameter, followed by POST /gh/v4/emails/test to generate an auto-login URL for that rebound contact.

5

Are affected versions identified?

All Groundhogg versions up to and including 4.9 are affected according to the provided data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203