What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.
Explanation of Vulnerability in Simple Terms
02Summary
The SendGrid for WordPress plugin through version 1.4 contains a SQL injection vulnerability that allows attackers to read sensitive data from the site's database. An attacker must trick a site administrator into visiting a malicious link. The vulnerability affects the plugin's query handling and can expose user information, email addresses, and other stored data without modifying or deleting it.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the WordPress database, including user information and email records.
Potential impact on your site
04Site Impact
Unauthorized access to user data, email addresses, and other database records stored by the plugin.
Conditions required to exploit
05Prerequisites
Network access and user interaction required; attacker must trick an admin into clicking a malicious link.
Key dates
06Disclosure timeline
August 29, 2024
CVE published
April 28, 2026
Record updated