CyberRota Analysis
AI-GeneratedThe Groundhogg CRM plugin for WordPress versions prior to 4.7.2 is vulnerable due to insufficient validation of redirect targets in its email preference confirmation flow. This flaw allows unauthenticated attackers to craft links that redirect users to arbitrary external URLs, potentially leading to phishing attacks or other malicious activities. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL by way of a crafted link.