CVE-2026-13226Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The AJAX handler wp_ajax_groundhogg_get_contacts_table has its capability check commented out and performs no nonce verification, meaning any authenticated user regardless of role can reach the vulnerable code path.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-26: 2PoC Mentioned / Linked · 2026-06-26: 1Technical Details · 2026-06-26: 206-26
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-13226-groundhogg-version-4-5-4-medium-vulnerability-proof-of-concept CVE-2026-13226 groundhogg (CVSS Score 6.5) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge #cybe…

    Post summary

    The tweet announces a proof‑of‑concept for CVE‑2026‑13226 affecting the WordPress Groundhogg plugin, links to the PoC, and provides basic technical details but does not discuss active exploitation or patches.

    0000051
    11 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13226 SQL Injection in Groundhogg CRM Plugin for WordPress Versions Up to 4.5.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13226

    Post summary

    The post announces CVE‑2026‑13226 as a SQL injection in Groundhogg CRM Plugin for WordPress versions up to 4.5.4 and provides a link to further details, but it does not include a PoC, exploit, active attack evidence, or patch information.

    00000115
    4.1K followersView on X

Explore more