CVE-2024-9364: SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wpmailplusclearlogs' function in all versions up to, and including, 1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's log files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9364?
CVE-2024-9364 is classified as a medium severity vulnerability due to unauthorized data loss potential.
How do I fix CVE-2024-9364?
To fix CVE-2024-9364, update the SendGrid for WordPress plugin to version 1.5 or newer.
Who is affected by CVE-2024-9364?
CVE-2024-9364 affects users of the SendGrid for WordPress plugin up to version 1.4.
What type of attack does CVE-2024-9364 allow?
CVE-2024-9364 allows authenticated attackers with Subscriber-level access to clear logs without sufficient permissions.
What functionality is compromised in CVE-2024-9364?
CVE-2024-9364 compromises the 'wp_mailplus_clear_logs' function due to its missing capability checks.