CVE-2026-11454: CWE-639 Authorization Bypass Through User-Controlled Key in trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation
Groundhogg CRM plugin for WordPress up to version 4.5.2 has an authorization bypass vulnerability via its REST API endpoint. Authenticated users with the view_contacts capability but without view_others_contacts can access any contact record, including sensitive personal information and user capabilities. This occurs because the endpoint lacks proper object-level ownership checks.
AI Analysis
Technical Summary
CVE-2026-11454 describes an Insecure Direct Object Reference vulnerability in the Groundhogg CRM, Newsletters, and Marketing Automation WordPress plugin. The REST endpoint GET /wp-json/gh/v4/contacts/<id> allows authenticated users with the view_contacts role capability to retrieve full contact records by sequential integer ID without verifying ownership. This bypasses intended restrictions for roles like Sales Rep, which should only access their own contacts. The exposed data includes personally identifiable information, contact metadata, owner IDs, admin edit URLs, and WordPress user capability sets linked to contacts.
Potential Impact
An attacker with authenticated access and the view_contacts capability can read any contact record on the site, including sensitive personal data and user privilege information. This compromises confidentiality but does not affect integrity or availability. The exposure of user capabilities could facilitate privilege escalation or further attacks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict the assignment of the view_contacts capability to trusted users only and monitor access to the REST API endpoint. Avoid granting roles like Sales Rep the view_contacts capability without additional controls.
CVE-2026-11454: CWE-639 Authorization Bypass Through User-Controlled Key in trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation
Description
Groundhogg CRM plugin for WordPress up to version 4.5.2 has an authorization bypass vulnerability via its REST API endpoint. Authenticated users with the view_contacts capability but without view_others_contacts can access any contact record, including sensitive personal information and user capabilities. This occurs because the endpoint lacks proper object-level ownership checks.
CVSS v3.1
Score 6.5medium
Affected software
trainingbusinesspros
Groundhogg — CRM, Newsletters, and Marketing Automation
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-11454 describes an Insecure Direct Object Reference vulnerability in the Groundhogg CRM, Newsletters, and Marketing Automation WordPress plugin. The REST endpoint GET /wp-json/gh/v4/contacts/<id> allows authenticated users with the view_contacts role capability to retrieve full contact records by sequential integer ID without verifying ownership. This bypasses intended restrictions for roles like Sales Rep, which should only access their own contacts. The exposed data includes personally identifiable information, contact metadata, owner IDs, admin edit URLs, and WordPress user capability sets linked to contacts.
Potential Impact
An attacker with authenticated access and the view_contacts capability can read any contact record on the site, including sensitive personal data and user privilege information. This compromises confidentiality but does not affect integrity or availability. The exposure of user capabilities could facilitate privilege escalation or further attacks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict the assignment of the view_contacts capability to trusted users only and monitor access to the REST API endpoint. Avoid granting roles like Sales Rep the view_contacts capability without additional controls.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-06-06T12:45:02.962Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a72e5c6bf8831d539734ef7
Added to database: 08/05/2026, 07:27:02 UTC
Last enriched: 08/12/2026, 15:53:27 UTC
Last updated: 09/17/2026, 22:01:32 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.