CVE-2026-81741

Summary

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.

Affected Software

VendorProductVersion RangeStatus
UnknownGroundhogg — CRM, Newsletters, and Marketing Automation0 < 4.7.2affected

Weaknesses

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References