Unrated severityNVD Advisory· Published Aug 30, 2026
CVE-2026-81660
CVE-2026-81660
Description
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.5.13
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.