WordPress Plugin Vulnerabilities

Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field

Description

The plugin does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.

Proof of Concept

Affects Plugins

Fixed in 4.5.13

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-28 (about 2 days ago)
Added
2026-08-28 (about 1 day ago)
Last Updated
2026-08-28 (about 1 day ago)

Other