CVE-2026-85310
Deferred Deferred - Pending Action

Path Traversal in Groundhogg Plugin

Vulnerability report for CVE-2026-85310, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Patchstack

Description

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
groundhogg groundhogg to 4.7.2 (exc)
groundhogg import_contacts 4.7.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Path Traversal vulnerability in the WordPress Groundhogg plugin versions 4.7.1 and earlier. It allows attackers to access unauthorized files or directories on the server by manipulating file paths in requests.

Detection Guidance

To detect this vulnerability, check if your Groundhogg plugin version is 4.7.1 or earlier. You can verify the version via WordPress admin panel under Plugins. No specific commands are provided, but monitoring for unusual file access patterns or unauthorized data exposure may help.

Impact Analysis

Attackers could exploit this to read sensitive files on your server, potentially exposing confidential data like configuration files, user credentials, or other sensitive information stored on the system.

Compliance Impact

This Path Traversal vulnerability in Groundhogg <= 4.7.1 could lead to unauthorized access or data exposure, which may violate compliance requirements under GDPR (data protection) and HIPAA (health data security) if sensitive user data is compromised. Unauthorized access risks breaching confidentiality obligations in these regulations.

Mitigation Strategies

Immediately update the Groundhogg plugin to version 4.7.2 or later. If updating is not possible, apply Patchstack's mitigation rule to block attacks temporarily and consult your hosting provider or a web developer for further assistance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85310. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart