Medium severity5.5OSV Advisory· Published Apr 1, 2025· Updated Jun 17, 2026
CVE-2025-1267
CVE-2025-1267
Description
The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions up to, and including, 3.7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=3.7.4.1+ 1 more
- (no CPE)range: <=3.7.4.1
- (no CPE)
- Range: 0.1, 0.9, 0.9.1, …
Patches
Vulnerability mechanics
References
5- github.com/groundhoggwp/groundhogg/commit/5206bf2482e2fe210ccca6e7dcfe62ffe85b3061nvd
- plugins.trac.wordpress.org/browser/groundhogg/trunk/assets/js/admin/forms/form-builder-v2.jsnvd
- plugins.trac.wordpress.org/browser/groundhogg/trunk/assets/js/admin/forms/form-builder-v2.jsnvd
- plugins.trac.wordpress.org/changeset/3264477/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/763a9aff-9bc0-4c79-9383-778a9034b436nvd
News mentions
0No linked articles in our index yet.