WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Groundhogg — CRM, Newsletters, and Marketing Automation

Groundhogg is the best WordPress CRM & Marketing Automation plugin. Create flows, email campaigns, and have a CRM all within your WordPress site.

34Reported vulnerabilities
8.8Highest CVSS score
4.5.15Latest version
2,000+Active installs

What to do now

Update Groundhogg — CRM, Newsletters, and Marketing Automation to 4.5.13 or later. 34 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 12, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2019-15647 High 8.8 4.5% Before 1.3.5 1.3.5 August 27, 2019
CVE-2023-1425 High 7.2 0.9% Before 2.7.9.4 2.7.9.4 April 10, 2023
CVE-2025-0394 High 8.8 1.1% 0 to 3.7.3.5 (inclusive) 3.7.3.6 January 14, 2025
CVE-2025-48300 High 8.8 0.4% 4.2.1 and earlier 4.2.2 July 4, 2025
WF-bc69ec54-b30f-402e-ad3b-24fd680ea72b High 8.8 1.3.11.13 and earlier 2.0.8 October 23, 2019
CVE-2026-57389 High 8.1 0.5% 4.4.1 and earlier 4.5 July 8, 2026
CVE-2026-40727 High 8.1 0.3% 4.4 and earlier 4.4.1 April 16, 2026
CVE-2023-2736 High 8 0.4% 2.7.9.8 and earlier 2.7.10 May 20, 2023
CVE-2025-4206 High 7.2 1.5% 0 to 4.1.1.2 (inclusive) 4.1.2 May 9, 2025
CVE-2025-54053 High 7.5 0.4% 4.2.2 and earlier 4.2.2.1 August 5, 2025
CVE-2026-81660 High 7.2 0.3% Before 4.5.13 4.5.13 August 31, 2026
CVE-2023-34179 High 7.2 0.7% 2.7.11 and earlier 2.7.11.1 May 30, 2023
CVE-2026-14029 Medium 6.5 0.6% 0 to 4.5.8 (inclusive) 4.5.9 July 2, 2026
CVE-2026-13333 Medium 6.5 0.6% 0 to 4.5.5 (inclusive) 4.5.6 June 27, 2026
CVE-2026-18387 Medium 6.5 0.4% 0 to 4.5.14 (inclusive) 4.5.15 August 15, 2026
CVE-2026-11454 Medium 6.5 0.4% 0 to 4.5.2 (inclusive) 4.5.3 August 5, 2026
CVE-2026-13331 Medium 6.5 0.5% 0 to 4.5.5 (inclusive) 4.5.6 June 27, 2026
CVE-2026-13226 Medium 6.5 0.5% 0 to 4.5.4 (inclusive) 4.5.5 June 26, 2026
CVE-2026-57667 Medium 6.5 0.4% 4.5 and earlier 4.5.1 June 26, 2026
CVE-2025-64367 Medium 6.4 0.2% 4.2.6 and earlier 4.2.6.1 October 31, 2025
CVE-2024-56289 Medium 6.1 0.7% 3.7.3.3 and earlier 3.7.3.4 January 3, 2025
CVE-2024-37264 Medium 6.1 0.3% 3.4.2.3 and earlier 3.4.3 June 27, 2024
WF-2052278d-f1df-4a31-8688-11c7c8d20e07 Medium 6.1 2.0.8.1 and earlier 2.0.9.11 September 10, 2019
CVE-2025-1267 Medium 5.5 0.3% 0 to 3.7.4.1 (inclusive) 4.0 April 1, 2025
CVE-2023-34178 Medium 5.4 0.3% 2.7.11 and earlier 2.7.11.1 May 30, 2023
CVE-2023-2735 Medium 5.4 0.5% 2.7.9.8 and earlier 2.7.10 May 20, 2023
CVE-2023-2716 Medium 5.4 0.5% 2.7.9.8 and earlier 2.7.10 May 20, 2023
CVE-2025-12750 Medium 4.9 0.3% 4.2.6.1 and earlier 4.2.7 November 20, 2025
CVE-2023-40681 Medium 4.4 0.3% 2.7.11.10 and earlier 2.7.11.11 October 25, 2023
CVE-2023-2715 Medium 4.3 0.6% 2.7.9.8 and earlier 2.7.10 May 20, 2023
CVE-2023-2714 Medium 4.3 0.5% 2.7.9.8 and earlier 2.7.10 May 20, 2023
CVE-2026-40793 Medium 4.3 0.3% Before 4.4.1 4.4.1 April 24, 2026
CVE-2024-37235 Medium 4.3 0.2% 3.4.2.3 and earlier 3.4.3 June 21, 2024
CVE-2023-2717 Medium 4.3 0.3% 2.7.9.8 and earlier 2.7.10 May 20, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.