CVE-2026-18387 | trainingbusinesspros Groundhogg Plugin up to 4.5.14 on WordPress Legacy Contact Query Legacy_Contact_Query tag_query sql injection

SecurityVulns

A vulnerability was found in trainingbusinesspros Groundhogg Plugin up to 4.5.14 on WordPress. It has been classified as problematic. This impacts the function Legacy_Contact_Query of the component Legacy Contact Query. This manipulation of the argument tag_query causes sql injection.

This vulnerability is tracked as CVE-2026-18387. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More