CVE-2026-104725: CWE-269 Improper Privilege Management in trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation
Description
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_users` or `promote_users` capabilities. This makes it possible for authenticated attackers, with sales_rep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the `{auto_login_link}` replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the `view_notes` and `add_notes` capabilities that the sales_rep role holds by default.
CVSS v3.1
Score 8.8high
Affected software
trainingbusinesspros
Groundhogg — CRM, Newsletters, and Marketing Automation
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104725 is a privilege escalation vulnerability in the Groundhogg WordPress plugin (versions up to 4.9). The vulnerability is due to a missing ownership and capability check on the user parameter in the process_edit() function. Authenticated users with the edit_contacts capability can reassign contact records to any WordPress user ID without requiring edit_users or promote_users capabilities. This allows attackers with sales_rep-level access to escalate privileges to administrator by linking a contact to an administrator's user ID, creating a note with an {auto_login_link} tag to generate a valid auto-login URL, and then using that URL to authenticate as the targeted administrator. The auto-login URL is accessible to attackers because the sales_rep role has view_notes and add_notes capabilities by default.
Potential Impact
An attacker with authenticated access and the edit_contacts capability can escalate privileges to administrator. This results in full control over the WordPress site, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 8.8 (high severity). The attacker can impersonate administrators by generating and using auto-login URLs tied to administrator accounts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict the edit_contacts capability to trusted users only and monitor for suspicious note creation or contact reassignment activities. Avoid granting sales_rep or similar roles unnecessary capabilities that could be abused. Follow vendor advisories for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-10-02T11:45:33.727Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac9d1c92cdf04f6560960cd
Added to database: 10/10/2026, 05:48:57 UTC
Last enriched: 10/10/2026, 06:18:14 UTC
Last updated: 10/10/2026, 21:27:29 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.