SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81741

MEDIUM · CVSS 4.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Groundhogg CRM plugin for WordPress versions prior to 4.7.2 is vulnerable due to insufficient validation of redirect targets in its email preference confirmation flow. This flaw allows unauthenticated attackers to craft links that redirect users to arbitrary external URLs, potentially leading to phishing attacks or other malicious activities. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-81741
Severity
MEDIUM
CVSS
4.7
EPSS
0.17%
WordPress

Original NVD Description

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.