/Vulnerability Library

SendGrid for WordPress <= 1.4 - SQL Injection

CVE-2024-43965
Verified

Description

Smackcoders SendGrid for WordPress [affected versions 1.4 and below] contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL queries, exploit requires crafted input.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Published Date

February 18, 2026

Template Author

shivam kamboj

CVE-2024-43965.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-43965
CWE ID:
cwe-89

References

https://nvd.nist.gov/vuln/detail/CVE-2024-43965https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-sendgrid-mailer/sendgrid-for-wordpress-14-unauthenticated-sql-injection

Remediation Steps

Update to the latest version of SendGrid for WordPress, version 1.5 or later.