CVE-2026-81741 - Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter
CVE ID :CVE-2026-81741
Published : Sept. 9, 2026, 6:17 a.m. | 48 minutes ago
Description :The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 9, 2026, 6:17 a.m. | 48 minutes ago
Description :The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...