CVE-2026-81741
Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
| Vendor | unknown |
| Product | groundhogg — crm, newsletters, and marketing automation |
| Published | Sep 9, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown groundhogg — crm, newsletters, and marketing automation
Be the first to know when new medium vulnerabilities affecting unknown groundhogg — crm, newsletters, and marketing automation are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Groundhogg — CRM, Newsletters, and Marketing Automation
0 < 4.7.2
References
Credits
Yaswanth Reddy Sunkara WPScan