CVE-2026-81741
Last modified
CVE-2026-81741 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Groundhogg — CRM, Newsletters, and Marketing Automation | < 4.7.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-81741?
How severe is CVE-2026-81741?
How do I fix CVE-2026-81741?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81733WWBN AVideo through 30.0 (and master up to commit 4cb576e) c…5.1
- CVE-2026-81735startServer.ts in the mcp-http-server package of UI-TARS-des…10
- CVE-2026-81736If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode…7.5
- CVE-2026-81737The FAQ Builder AYS WordPress plugin before 1.8.5 does not s…8.8
- CVE-2026-81738OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows…2.3
- CVE-2026-8174Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-S…5.7
- CVE-2026-81742The BE REST Endpoints WordPress plugin through 1.0.0 does no…8.8
- CVE-2026-81743Affected versions of Flowintel allow the LOG_FILE configurat…7.5
- CVE-2026-8175IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 …9.8
- CVE-2026-81753Affected versions of Flowintel render Mermaid blocks contain…5.1
- CVE-2026-81754The Vigilant – 100% Free Security Suite: Firewall, 2FA, Logi…7.2
- CVE-2026-81756Unauthenticated SQL Injection in Smart Marketing SMS and New…9.3
Are you affected by CVE-2026-81741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
