Input validation vulnerability in Groundhogg — CRM, Newsletters, and Marketing Automation 4.2.6.1

The Groundhogg plugin for WordPress, which helps with customer relations, newsletters, and marketing automation, has a vulnerability that allows hackers to inject malicious code through the ‘term’ parameter. This can happen in all versions up to 4.2.6.1 because the plugin does not properly protect against user input and does not prepare the SQL query properly. This means that attackers with high-level access can add their own code into existing queries and potentially access sensitive information from the database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.