CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97644

HIGHCVSS 8.8NVD feed

Published 3 October 2026 · tracked since 3 October 2026

Description

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contact

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-97644 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97644

HIGHCVSS 8.8NVD feed

Published 3 October 2026 · tracked since 3 October 2026

Description

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contact

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]