The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-30 07:17
Updated : 2026-08-31 20:14
NVD link : CVE-2026-81660
Mitre link : CVE-2026-81660
CVE.ORG link : CVE-2026-81660
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
