CVE-2026-97644 | trainingbusinesspros Groundhogg Plugin up to 4.9 on WordPress Contact Identity Rebinding /gh/v3/contacts create_contact user_id privileges management
A vulnerability, which was classified as critical, has been found in trainingbusinesspros Groundhogg Plugin up to 4.9 on WordPress. This affects the function create_contact of the file /gh/v3/contacts of the component Contact Identity Rebinding. The manipulation of the argument user_id leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-97644. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More