CVE-2026-92975
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation i
Summary
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.3 via the `create_support_user()` function. This is due to the function identifying the support account solely by matching against publicly hardcoded constants — `user_login` `'groundhogg'` and email addresses `'[email protected]'` / `'[email protected]'` — where the `in_array()` email-equality check at line 238 is not a security boundary because any user fully controls their own email value. This makes it possible for an attacker with an account whose `user_login` is `'groundhogg'` and whose `user_email` matches one of the hardcoded support constants to have that account silently promoted to administrator — and additionally to super admin on multisite when the triggering administrator holds `manage_network_options` — resulting in full site takeover. Exploitation requires a two-actor flow: the attacker must first obtain or pre-plant an account with the hardcoded credentials (possible when open user registration is enabled or another account-creation path exists), after which a legitimate administrator must invoke the support-access feature via the `submit_ticket` or `process_send_support_access` entry points to trigger the promotion.
Published 2026-10-10 · first seen here 2026-10-10
Analysis & write-ups
No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.
Where it shows in your logs
Server or web application · Local privilege escalation medium confidence
What to look for
- SYSTEM or root processes started from a non-admin user's session
- Known exploit tool names or unsigned binaries run from user-writable folders (Temp, Downloads, /tmp)
- The application's process (w3wp.exe, java, tomcat, node, php-fpm, httpd, python) starting shells or LOLBins (cmd, powershell, sh, bash, curl, wget, certutil)
- New script files in web roots (.jsp, .aspx, .php): a web shell
- Requests to unusual URLs on the application from internet IPs right before any of the above
- Outbound connections from the server to new external IPs
Data sources
Web server and WAF logs · ATT&CK DS0015 Application Log Content
- Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession- Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes- CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs
Process creation · ATT&CK DS0009 Process Creation
- Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate- Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)- CrowdStrike
ProcessRollup2SyntheticProcessRollup2
File creation · ATT&CK DS0022 File Creation
- Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent- Splunk
Endpoint.FilesystemSysmon Event ID 11- CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events
Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow
- Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession- Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)- CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6
Account and group changes · ATT&CK DS0002 User Account Creation / Modification
- Sentinel
SecurityEvent (4720, 4728, 4732, 4756)AuditLogsIdentityDirectoryEvents- Splunk
Change.All_Changes (Account_Management)WinEventLog:Security (4720, 4732)- CrowdStrike
UserAccountCreatedUserAccountAddedToGroup
A generic baseline worked out from the product type and weakness (CWE-269), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.
References
- NVD entry
- https://github.com/groundhoggwp/groundhogg/commit/4b413aa6e
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.1/admin/help/help-page.php#L224
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.1/admin/help/help-page.php#L238
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.1/admin/help/help-page.php#L250
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.1/admin/help/help-page.php#L298
- https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.8.1/admin/help/help-page.php#L599
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c355658a-515a-48ed-a114-6a202e23e34b?source=cve