CVE-2021-34629: SendGrid <= 1.11.8 – Authorization Bypass
The SendGrid WordPress plugin is vulnerable to authorization bypass via the getajaxstatistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34629?
CVE-2021-34629 is classified as a high severity vulnerability due to the ease of exploitation and potential data exposure.
How do I fix CVE-2021-34629?
To mitigate CVE-2021-34629, update the SendGrid WordPress plugin to version 1.11.9 or later.
What systems are affected by CVE-2021-34629?
CVE-2021-34629 affects the SendGrid plugin for WordPress versions up to and including 1.11.8.
Who can exploit CVE-2021-34629?
CVE-2021-34629 can be exploited by authenticated users with access to the WordPress multi-site administration.
What does CVE-2021-34629 allow attackers to do?
CVE-2021-34629 allows attackers to bypass authorization and export statistics from a WordPress multi-site main site.