Extension WordPress

Vulnérabilités Groundhogg , CRM, Newsletters, and Marketing Automation

Cette page rassemble les failles publiées pour Groundhogg , CRM, Newsletters, and Marketing Automation, leurs plages de versions affectées et les correctifs signalés dans la base locale.

31Vulnérabilités
0Critiques
31Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Groundhogg , CRM, Newsletters, and Marketing Automation

31 fiches

CVE-2026-57389 Élevée · 8,1
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg , CRM, Newsletters, and Marketing Automation <= 4.4.1 – Authenticated (Sales Representative+) Arbitrary File Deletion

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers,…

Versions affectées

*-4.4.1

Correctif

4.5

Publication

08/07/2026

CVE-2026-14029 Moyenne · 6,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 4.5.8 – Authenticated (Custom+) SQL Injection via 'select' Parameter

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in all versions up to, and including, 4.5.8 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-4.5.8

Correctif

4.5.9

Publication

01/07/2026

CVE-2026-13333 Moyenne · 6,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 4.5.5 – Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-4.5.5

Correctif

4.5.6

Publication

26/06/2026

CVE-2026-57667 Moyenne · 6,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg , CRM, Newsletters, and Marketing Automation <= 4.5 – Authenticated (Sales representative+) SQL Injection

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

Versions affectées

*-4.5

Correctif

4.5.1

Publication

26/06/2026

CVE-2026-13331 Moyenne · 6,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 4.5.5 – Authenticated (Marketer+) SQL Injection via 'search' Parameter

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-4.5.5

Correctif

4.5.6

Publication

26/06/2026

CVE-2026-13226 Moyenne · 6,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 4.5.4 – Authenticated (Custom+) SQL Injection via 'after' Parameter

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-4.5.4

Correctif

4.5.5

Publication

25/06/2026

CVE-2026-40793 Moyenne · 4,3
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg , CRM, Newsletters, and Marketing Automation < 4.4.1 – Missing Authorization

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.4.1. This makes it possible for authenticated attackers, with…

Versions affectées

[*, 4.4.1)

Correctif

4.4.1

Publication

24/04/2026

CVE-2026-40727 Élevée · 8,1
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg , CRM, Newsletters, and Marketing Automation <= 4.4 – Authenticated (Sales Representative+) Arbitrary File Deletion

The Groundhogg , CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 4.4. This makes it possible for authenticated attackers,…

Versions affectées

*-4.4

Correctif

4.4.1

Publication

16/04/2026

CVE-2025-64367 Moyenne · 6,4
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 4.2.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-4.2.6

Correctif

4.2.6.1

Publication

31/10/2025

CVE-2025-54053 Élevée · 7,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 4.2.2 – Authenticated (Sales Representative+) PHP Object Injection

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner , Groundhogg plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.2 via deserialization of untrusted input. This makes…

Versions affectées

*-4.2.2

Correctif

4.2.2.1

Publication

05/08/2025

CVE-2025-4206 Élevée · 7,2
Groundhogg , CRM, Newsletters, and Marketing Automation

WordPress CRM, Email & Marketing Automation for WordPress | Award Winner , Groundhogg <= 4.1.1.2 – Authenticated (Administrator+) Arbitrary File Deletion

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner , Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'process_export_delete' and 'process_import_delete' functions in all versions…

Versions affectées

*-4.1.1.2

Correctif

4.1.2

Publication

08/05/2025

CVE-2025-1267 Moyenne · 5,5
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 3.7.4.1 – Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter

The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions up to, and including, 3.7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-3.7.4.1

Correctif

4.0

Publication

31/03/2025

CVE-2025-0394 Élevée · 8,8
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 3.7.3.5 – Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner , Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to,…

Versions affectées

*-3.7.3.5

Correctif

3.7.3.6

Publication

13/01/2025

CVE-2024-56289 Moyenne · 6,1
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 3.7.3.3 – Reflected Cross-Site Scripting

The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-3.7.3.3

Correctif

3.7.3.4

Publication

03/01/2025

CVE-2024-37264 Moyenne · 6,1
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 3.4.2.3 – Reflected Cross-Site Scripting

The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-3.4.2.3

Correctif

3.4.3

Publication

27/06/2024

CVE-2024-37235 Moyenne · 4,3
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 3.4.2.3 – Cross-Site Request Forgery

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2.3. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions…

Versions affectées

*-3.4.2.3

Correctif

3.4.3

Publication

21/06/2024

CVE-2023-40681 Moyenne · 4,4
Groundhogg , CRM, Newsletters, and Marketing Automation

Groundhogg <= 2.7.11.10 – Authenticated (Administrator+) Stored Cross-Site Scripting via Task Data

The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via task data in versions up to, and including, 2.7.11.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-2.7.11.10

Correctif

2.7.11.11

Publication

25/10/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités