Confidence
Medium. Based on ~13 public sources; no independent review aggregates (G2, Capterra) found in evidence.
Pricing
Flat-rate premium plans
Not disclosed in reviewed sources
ModelFlat-rate
Monthly feesNot disclosed
HardwareNot disclosed
Sources & method
Analyzed 9/20/2026 - 13 sources - Multiple CVEs (stored XSS, CSRF, path traversal, unauthorized data access) plus a disclosed June 2025 supply-chain attack; patching discipline is mandatory.
official x4review x2security x6news x1
- CVE-2026-81660 — unauthenticated stored XSS in web forms, Versions before 4.5.13 do not validate or escape some optional web form submissions.
- CVE-2023-2716 — unauthorized data access, The plugin is vulnerable to unauthorized access of data.
- CVE-2026-81741 — CSRF vulnerability, Cross-site request forgerness issue in the Groundhogg WordPress plugin.
- CVE-2026-57389 — path traversal, Path traversal vulnerability in the Groundhogg plugin.
- Supply chain attack, June 27, 2025, Vendor disclosed a targeted supply chain attack and is notifying affected customers.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.