Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-81660: Groundhogg plugin lets attackers inject code via form

CVE-2026-81660 · published 4 days ago
Summary

The Groundhogg CRM and marketing plugin for WordPress, versions before 4.5.13, does not properly clean data entered in certain form fields. This allows anyone on the internet to add hidden code that will run when an administrator views the form, potentially compromising the site. Update the plugin to the latest version or apply the vendor’s fix and restrict who can submit those forms.

What to do
  • Update unknown groundhogg — crm, newsletters, and marketing automation to version 4.5.13 or later.
Affected software
VendorProductAffected versions
unknown groundhogg — crm, newsletters, and marketing automation < 4.5.13
Original advisory text
Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.
References
Severity
8.8 High
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Sources
CVE-2026-81660 · MITRE
Monitor software like this
Free during beta