Access violation vulnerability in WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg 2.7.9.8

The Groundhogg plugin for WordPress is vulnerable to unauthorized access and modification of data. This vulnerability affects versions up to 2.7.9.8. It makes it possible for an attacker who has subscriber-level access or higher to upload a file to a contact and then view all other files related to that contact. This vulnerability can be easily exploited and should be addressed immediately.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.