CVE-2026-92975
Received Received - Intake

Privilege Escalation in Groundhogg WordPress Plugin

Vulnerability report for CVE-2026-92975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.3 via the `create_support_user()` function. This is due to the function identifying the support account solely by matching against publicly hardcoded constants β€” `user_login` `'groundhogg'` and email addresses `'support@groundhogg.io'` / `'help@groundhogg.io'` β€” where the `in_array()` email-equality check at line 238 is not a security boundary because any user fully controls their own email value. This makes it possible for an attacker with an account whose `user_login` is `'groundhogg'` and whose `user_email` matches one of the hardcoded support constants to have that account silently promoted to administrator β€” and additionally to super admin on multisite when the triggering administrator holds `manage_network_options` β€” resulting in full site takeover. Exploitation requires a two-actor flow: the attacker must first obtain or pre-plant an account with the hardcoded credentials (possible when open user registration is enabled or another account-creation path exists), after which a legitimate administrator must invoke the support-access feature via the `submit_ticket` or `process_send_support_access` entry points to trigger the promotion.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trainingbusinesspros Groundhogg β€” CRM, Newsletters, and Marketing Automation 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to escalate their privileges to administrator or super administrator level in a WordPress site running the Groundhogg plugin up to version 4.8.3. The issue occurs because the plugin's support user creation function checks for a hardcoded username and email to identify support accounts, but these checks are not secure. An attacker can create an account with the username 'groundhogg' and an email matching the plugin's support addresses, then trick an administrator into triggering the support feature, which silently promotes the attacker's account to full admin access.

Detection Guidance

Check for user accounts with login 'groundhogg' and email 'support@groundhogg.io' or 'help@groundhogg.io'. Inspect WordPress user roles for unexpected administrator or super administrator privileges. Review plugin versions to confirm if Groundhogg versions up to 4.8.3 are installed.

Impact Analysis

If you use the Groundhogg plugin on your WordPress site, an attacker could gain full control of your site, including the ability to install malicious plugins, steal data, or deface your website. This requires the attacker to first create an account with specific credentials and then trick an administrator into using the support feature. Sites with open user registration are more vulnerable.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations. A full site takeover may result in data breaches, unauthorized data access, or loss of data integrity, all of which are critical compliance violations requiring breach notifications and potential fines.

Mitigation Strategies

Update the Groundhogg plugin to the latest version beyond 4.8.3. Disable open user registration if enabled. Audit user accounts for unauthorized administrator or super administrator roles and remove any suspicious accounts. Monitor for unusual activity related to support access features.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart