medium
CVE-2026-81660
Groundhogg stored cross-site scripting - optional web-form fields are stored and rendered unescaped
- Severity
- medium
- Affected product
- groundhogg
- Affected versions
- groundhogg < 4.5.13
- Fixed in
- groundhogg 4.5.13
- Added to NewScan
- 2026-08-30
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints groundhogg from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source; slug verified against api.wordpress.org ('Groundhogg - CRM, Newsletters, and Marketing Automation', current 4.7.1). The submission path is the plugin's public web form, so the payload is planted unauthenticated and fires for whoever reads the contact record. Version-match only: proving it means storing a script payload in a stranger's CRM.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →