WPセキュリティ診断脆弱性データ 2026年10月10日 時点 フォローして新着情報を受け取る

CVE-2026-104725

Groundhogg — CRM, Newsletters, and Marketing Automation に報告された脆弱性

高深刻度
8.8CVSS
4.9.1修正されたバージョン
—30日以内に悪用される確率

概要

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_users` or `promote_users` capabilities. This makes it possible for authenticated attackers, with sales_rep-level access and above, to escalate their privileges to administrator by linking a contact to an administrator's WordPress user ID, then creating a note containing the `{auto_login_link}` replacement tag to trigger generation of a valid auto-login permissions-key URL for the administrator-linked contact, and finally visiting that URL to authenticate as the targeted administrator. The auto-login URL is stored in the note content and is readable back by the attacker via the `view_notes` and `add_notes` capabilities that the sales_rep role holds by default.

CWE: CWE-269 / 公開 2026年10月9日 / 最終更新 2026年10月9日

影響を受けるバージョン

対処方法

Groundhogg — CRM, Newsletters, and Marketing Automation を 4.9.1 以降に更新してください。これで本脆弱性は解消します。

提供元の推奨: Update to version 4.9.1, or a newer patched version

Groundhogg — CRM, Newsletters, and Marketing Automation の他の脆弱性を見る →

あなたのサイトは大丈夫ですか?

URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。

30秒で無料診断する

参照

この脆弱性情報の一部は Wordfence Intelligence から取得しています。 原本: https://www.wordfence.com/threat-intel/vulnerabilities/id/715b4d10-b19a-4b37-8a76-985c37975c93

Copyright 2012-2026 Defiant Inc. / ライセンス全文