CVE-2024-43965 HIGH

CVE-2024-43965: WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability

Vendor Smackcoders
Product SendGrid for WordPress
Weakness CWE-89 · SQLi
Published August 29, 2024
Last update April 28, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.

Explanation of Vulnerability in Simple Terms

02Summary

The SendGrid for WordPress plugin through version 1.4 contains a SQL injection vulnerability that allows attackers to read sensitive data from the site's database. An attacker must trick a site administrator into visiting a malicious link. The vulnerability affects the plugin's query handling and can expose user information, email addresses, and other stored data without modifying or deleting it.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the WordPress database, including user information and email records.

Potential impact on your site

04Site Impact

Unauthorized access to user data, email addresses, and other database records stored by the plugin.

Conditions required to exploit

05Prerequisites

Network access and user interaction required; attacker must trick an admin into clicking a malicious link.

Key dates

06Disclosure timeline

August 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE