WordPress Plugin Vulnerabilities
SendGrid <= 1.11.8 - Authenticated Authorization Bypass
Description
The plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistics for a WordPress multi-site main site in versions up to 1.11.8. This vulnerability only affects the main site of WordPress multi-site installations.
Proof of Concept
Affects Plugins
References
Classification
Type
AUTHBYPASS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Prashant Baldha
Submitter
Wordfence
Submitter website
Verified
No
WPVDB ID
Timeline
Publicly Published
2021-07-21 (about 4 years ago)
Added
2021-07-21 (about 4 years ago)
Last Updated
2022-04-12 (about 3 years ago)