← All CVEs NewScan detects
medium

CVE-2026-81660

Groundhogg stored cross-site scripting - optional web-form fields are stored and rendered unescaped

Severity
medium
Affected product
groundhogg
Affected versions
groundhogg < 4.5.13
Fixed in
groundhogg 4.5.13
Added to NewScan
2026-08-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints groundhogg from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source; slug verified against api.wordpress.org ('Groundhogg - CRM, Newsletters, and Marketing Automation', current 4.7.1). The submission path is the plugin's public web form, so the payload is planted unauthenticated and fires for whoever reads the contact record. Version-match only: proving it means storing a script payload in a stranger's CRM.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →