天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-97644 WordPress Groundhogg 插件权限提升漏洞

影响攻击者可提升为管理员并接管 WordPress 站点

AI 研判

Groundhogg 是 WordPress 的 CRM、邮件营销与营销自动化插件。其 v3 REST 接口的 create_contact 函数仅校验 add_contacts 权限,并将包含 user_id 字段的完整请求体传入 Contacts_DB::add() 的 upsert 路径,绕过了 Contacts_DB::update() 中的归属校验。攻击者可借此将联系人记录重新绑定到任意 WordPress 用户 ID,进而获取管理员会话。

影响范围

Groundhogg

Groundhogg 所有版本至 4.9(含 4.9)。

漏洞详情

漏洞属于权限提升,成因是 v3 REST 接口 POST /gh/v3/contacts 的 create_contact 仅以 add_contacts 能力作为门槛,且未过滤 user_id 字段,直接进入 Contacts_DB::add() 的 upsert 流程,绕过了 update() 中的归属保护。拥有 Sales Representative 及以上权限的已认证攻击者可将自己的联系人记录绑定到管理员用户 ID,再调用 v4 邮件测试接口 POST /gh/v4/emails/test 生成绑定该联系人的 {auto_login_url} 一次性登录密钥,访问该链接即可通过 wp_set_auth_cookie() 获得管理员身份。

利用条件与风险

利用前提是攻击者需具备 Sales Representative 及以上权限的已认证账户,且目标站点启用了相关 REST 接口。成功利用后可完全接管 WordPress 站点,实战风险高。

修复建议

建议升级 Groundhogg 至 4.9 之后的修复版本;若暂无可用更新,可限制或禁用 v3 contacts 与 v4 emails/test 接口的访问,并审查具备 add_contacts、send_emails 能力的账户权限。具体修复版本请以官方公告为准。

原始情报

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator’s user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.