Access violation vulnerability in WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg 2.7.8.9

The Groundhogg plugin for WordPress has a security vulnerability in versions up to, and including, 2.7.9.8. It can allow unauthorized access to the website’s data without a proper security check. An attacker who is authenticated can create a support ticket that sends the website’s data to the plugin developer, and can also create an admin access with an auto login link that is also sent to the plugin developer with the ticket. This vulnerability only works if the plugin is activated with a valid license.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.