Input validation vulnerability in WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg 2.7.9.8

The Groundhogg plugin for WordPress has a security flaw in versions up to 2.7.9.8. This flaw can be used by attackers who are logged in to the site to get the auto login link and then use it to change the user assigned to it. This can be done by tricking a site administrator into taking an action, such as clicking a link. As a result, the attacker can gain more privileges than they should have.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.