CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-0394: Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function

8.8 CVSS

Description

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Classification

CVE ID: CVE-2025-0394

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

Affected Products

Vendor: trainingbusinesspros

Product: WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.07% (probability of being exploited)

EPSS Percentile: 31.41% (scored less or equal to compared to others)

EPSS Date: 2025-02-12 (when was this score calculated)

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/b2cf3b85-2e2d-43dc-9877-9a740d4fd2fb?source=cve
https://plugins.trac.wordpress.org/browser/groundhogg/tags/3.7.3.5/includes/big-file-uploader.php#L117
https://wordpress.org/plugins/groundhogg/#developers
https://plugins.trac.wordpress.org/changeset/3221208/

Timeline