CVE-2026-81741
Deferred Deferred - Pending Action

Open Redirect in Groundhogg WordPress Plugin

Vulnerability report for CVE-2026-81741, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: WPScan

Description

The Groundhogg β€” CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
groundhogg groundhogg to 4.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an open redirect issue in the Groundhogg WordPress plugin versions before 4.7.2. The email preference confirmation flow does not restrict the redirect target URL to the site's domain, allowing attackers to craft links that redirect users to arbitrary external websites.

Detection Guidance

To detect this vulnerability, check the Groundhogg plugin version on your WordPress site. If it is below 4.7.2, the site is vulnerable. Inspect network traffic for suspicious redirect requests in the email preference confirmation flow, particularly looking for the 'redirect_to' parameter pointing to external domains.

Impact Analysis

Unauthenticated attackers could trick users into clicking malicious links, leading to phishing attacks, malware downloads, or exposure to malicious websites. Users might unknowingly share sensitive information or have their sessions compromised.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face fines or penalties for failing to protect user data adequately.

Mitigation Strategies

Immediately update the Groundhogg plugin to version 4.7.2 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Monitor for any unusual redirect activity in web server logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81741. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart