CVE-2025-48301: WordPress SMTP for SendGrid – YaySMTP plugin <= 1.5 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP allows SQL Injection. This issue affects SMTP for SendGrid – YaySMTP: from n/a through 1.5.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP smtp-sendgrid allows SQL Injection.This issue affects SMTP for SendGrid – YaySMTP: from n/a through <= 1.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48301?
CVE-2025-48301 is classified as a critical severity vulnerability due to its potential for SQL Injection.
How do I fix CVE-2025-48301?
To fix CVE-2025-48301, upgrade your YayCommerce SMTP for SendGrid – YaySMTP to version 1.6 or later.
What versions are affected by CVE-2025-48301?
CVE-2025-48301 affects YayCommerce SMTP for SendGrid – YaySMTP versions up to and including 1.5.
Which systems are impacted by CVE-2025-48301?
CVE-2025-48301 impacts both YayCommerce SMTP for SendGrid and WordPress SMTP for SendGrid that use versions up to 1.5.
What type of vulnerability is CVE-2025-48301?
CVE-2025-48301 is an SQL Injection vulnerability that allows improper neutralization of special elements in SQL commands.