Groundhogg — CRM, Newsletters, and Marketing Automation < 4.4.1 - Missing Authorization
Groundhogg — CRM, Newsletters, and Marketing Automation
Minimum safe version
4.4.1
Update to 4.4.1 or later to address 27 fixable vulnerabilities
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.4 - Authenticated (Sales Representative+) Arbitrary File Deletion
CVE-2025-12750
CVE-2025-64367
CVE-2025-54053
CVE-2025-48300
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion
Groundhogg <= 3.7.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter
Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function
CVE-2024-56289
CVE-2024-37264
CVE-2024-37235
CVE-2023-40681
CVE-2023-34179
CVE-2023-34178
WordPress Groundhogg Plugin <= 2.7.9.8 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-2735
CVE-2023-2717
WordPress Groundhogg Plugin <= 2.7.9.8 is vulnerable to Broken Access Control
CVE-2023-2715
CVE-2023-2714
Groundhogg <= 2.0.8.1 - Authenticated Reflected XSS
Groundhogg <= 1.3.11.3 - Authenticated SQL Injection
WordPress Groundhogg Plugin < 2.7.9.4 is vulnerable to SQL Injection
Groundhogg <= 2.0.8.1 - Reflected Cross-Site Scripting
Groundhogg <= 1.3.11.13 - SQL Injection
CVE-2019-15647