CVE-2025-48301

7.6

YayCommerce · SMTP for SendGrid – YaySMTP

YayCommerce SMTP for SendGrid – YaySMTP contains an SQL injection vulnerability that allows authenticated attackers with administrative privileges to execute arbitrary SQL commands.

Executive summary

A critical SQL injection vulnerability in the YayCommerce SMTP for SendGrid plugin allows authenticated administrative users to compromise database integrity and confidentiality.

Vulnerability

The plugin fails to properly neutralize special elements used in SQL commands, resulting in an SQL injection vulnerability. This flaw requires the attacker to have administrative privileges to successfully trigger the injection.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive database information, potential data exfiltration, or modification of application settings. Given the CVSS score of 7.6, this represents a high-severity risk to the confidentiality and availability of the WordPress environment, necessitating prompt remediation to prevent database compromise.

Remediation

Immediate Action: Administrators should verify if an update beyond version 1.5 is available via the WordPress plugin repository and apply it immediately. If no update is available, consider disabling or removing the plugin until a secure version is released.

Proactive Monitoring: Review database query logs for unusual or unauthorized SQL syntax and monitor administrative access logs for suspicious account activity.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting WordPress plugins.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability presents a significant risk to the integrity of the underlying database. Organizations utilizing this plugin must prioritize verifying the patch status of their installation and ensure that administrative access is restricted to authorized personnel only. Apply the latest available update as soon as it is published to mitigate this exposure.

More YayCommerce CVEs

Sources

Originally found and disclosed by Lê Quốc Bảo | Patchstack Bug Bounty Program, per the CVE Program record.