Skip to main content
EPSS 0.3%top 75%

CVE-2026-104725: CWE-269 Improper Privilege Management in trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation

0
High
Published: 10/10/2026 (10/10/2026, 06:30:58 UTC)
Source: CVE Database V5
Vendor/Project: trainingbusinesspros
Product: Groundhogg — CRM, Newsletters, and Marketing Automation

Description

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_users` or `promote_users` capabilities. This makes it possible for authenticated attackers, with sales_rep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the `{auto_login_link}` replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the `view_notes` and `add_notes` capabilities that the sales_rep role holds by default.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

trainingbusinesspros

Groundhogg — CRM, Newsletters, and Marketing Automation

Affected versions
>=0 <=4.9

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/10/2026, 06:18:14 UTC

Technical Analysis

CVE-2026-104725 is a privilege escalation vulnerability in the Groundhogg WordPress plugin (versions up to 4.9). The vulnerability is due to a missing ownership and capability check on the user parameter in the process_edit() function. Authenticated users with the edit_contacts capability can reassign contact records to any WordPress user ID without requiring edit_users or promote_users capabilities. This allows attackers with sales_rep-level access to escalate privileges to administrator by linking a contact to an administrator's user ID, creating a note with an {auto_login_link} tag to generate a valid auto-login URL, and then using that URL to authenticate as the targeted administrator. The auto-login URL is accessible to attackers because the sales_rep role has view_notes and add_notes capabilities by default.

Potential Impact

An attacker with authenticated access and the edit_contacts capability can escalate privileges to administrator. This results in full control over the WordPress site, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 8.8 (high severity). The attacker can impersonate administrators by generating and using auto-login URLs tied to administrator accounts.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict the edit_contacts capability to trusted users only and monitor for suspicious note creation or contact reassignment activities. Avoid granting sales_rep or similar roles unnecessary capabilities that could be abused. Follow vendor advisories for updates and apply patches promptly once released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Wordfence
Date Reserved
2026-10-02T11:45:33.727Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac9d1c92cdf04f6560960cd

Added to database: 10/10/2026, 05:48:57 UTC

Last enriched: 10/10/2026, 06:18:14 UTC

Last updated: 10/10/2026, 21:27:29 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses