WP脆弱性ウォッチ脆弱性データ 2026年10月3日 時点

CVE-2026-97644

Groundhogg — CRM, Newsletters, and Marketing Automation に報告された脆弱性

高深刻度
8.8CVSS
4.9.1修正されたバージョン
—30日以内に悪用される確率

概要

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.

CWE: CWE-269 / 公開 2026年10月2日 / 最終更新 2026年10月2日

影響を受けるバージョン

対処方法

Groundhogg — CRM, Newsletters, and Marketing Automation を 4.9.1 以降に更新してください。これで本脆弱性は解消します。

提供元の推奨: Update to version 4.9.1, or a newer patched version

Groundhogg — CRM, Newsletters, and Marketing Automation の他の脆弱性を見る →

あなたのサイトは大丈夫ですか?

URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。

30秒で無料診断する

参照

この脆弱性情報の一部は Wordfence Intelligence から取得しています。 原本: https://www.wordfence.com/threat-intel/vulnerabilities/id/557306b7-7b66-465e-8d4d-ebae5b1577c9

Copyright 2012-2026 Defiant Inc. / ライセンス全文