The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 06:17
Updated : 2026-09-09 16:17
NVD link : CVE-2026-81741
Mitre link : CVE-2026-81741
CVE.ORG link : CVE-2026-81741
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
