CVE-2026-81660 PUBLISHED

Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field

Assigner: WPScan
Reserved: 27.08.2026 Published: 30.08.2026 Updated: 30.08.2026

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.

Product Status

Vendor Unknown
Product Groundhogg — CRM, Newsletters, and Marketing Automation
Versions Default: unaffected
  • affected from 0 to 4.5.13 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE