Sceawere
Vulnerability Detail
CVE-2026-104725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Groundhogg Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 2h ago
- Vendor
- trainingbusinesspros
- Product
- Groundhogg — CRM, Newsletters, and Marketing Automation
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_users` or `promote_users` capabilities. This makes it possible for authenticated attackers, with sales_rep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the `{auto_login_link}` replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the `view_notes` and `add_notes` capabilities that the sales_rep role holds by default.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-10T06:16:38.920Z",
"pubdate": "2026-10-10T06:16:38.920Z",
"executiveSummary": "Groundhogg versions up to and including 4.9 contain a critical privilege escalation vulnerability rooted in improper authorization checks. The vulnerability allows authenticated users with the 'edit_contacts' capability, such as the 'sales_rep' role, to modify the association between contact records and WordPress user IDs.\nBy manipulating the 'user' parameter in the 'process_edit()' function, an attacker can reassign a contact record to an administrative WordPress user ID. This action bypasses standard WordPress permission structures, specifically the requirement for 'edit_users' or 'promote_users' capabilities. The exploit culminates in the generation of a valid '{auto_login_link}' via the note-creation feature. As the attacker possesses the 'view_notes' capability, they can retrieve the sensitive auto-login URL generated for the now-linked administrative account. Accessing this URL grants the attacker full administrative authentication, leading to complete site compromise. Given that this exploit requires only a low-privileged authenticated account ('sales_rep' level), the risk to confidentiality, integrity, and availability is considered severe.",
"technicalDetails": "The vulnerability resides within the 'process_edit()' function of the Groundhogg plugin. The root cause is a failure to perform adequate ownership and capability validation on the 'user' parameter during contact record modification. While the system checks if the user has the 'edit_contacts' capability, it fails to verify if the user possesses the requisite administrative permissions ('edit_users' or 'promote_users') to manipulate user-to-contact associations.\nExploitation follows a specific, multi-stage attack flow. First, an authenticated attacker with 'edit_contacts' capability identifies or creates a contact record. The attacker then invokes the 'process_edit()' function, injecting an arbitrary WordPress user ID (typically that of an administrator) into the 'user' parameter of the request. The plugin's logic processes this request without secondary validation, effectively linking the high-privileged administrative account to the attacker-controlled contact entry.\nOnce the association is established, the attacker utilizes the plugin's note creation functionality. By including the '{auto_login_link}' replacement tag within the note content, the attacker triggers the plugin's internal mechanism to generate a valid, time-sensitive auto-login URL associated with the linked user record. Because the attacker holds the 'view_notes' capability by default, they can retrieve the note content—and the contained auto-login URL—directly through the plugin's interface.\nThe final stage involves the attacker navigating to the captured '{auto_login_link}'. Upon visiting this URL, the plugin authenticates the requester as the target administrator. This grants the attacker full administrative access to the WordPress environment, bypassing standard login procedures. This vulnerability is particularly potent because it converts a limited 'sales_rep' privilege level into full 'administrator' access without requiring knowledge of the administrator's password or bypassing MFA if the auto-login mechanism is treated as a trusted bypass. The lack of validation on the backend ensures that the 'process_edit()' function remains a primary vector for account association manipulation across all versions up to 4.9."
}