Description
WordPress Plugin SendGrid is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently export statistics for a WordPress multi-site main site. WordPress Plugin SendGrid version 1.11.8 is vulnerable; prior versions are also affected.
Remediation
Disable and remove the plugin until a fix is available
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-34629
https://wordpress.org/plugins/sendgrid-email-delivery-simplified/#description
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3747)
MySQL CVE-2021-2038 Vulnerability (CVE-2021-2038)
Jenkins Incorrect Authorization Vulnerability (CVE-2017-2599)
Joomla URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-24598)
Product Reviews Import Export for WooCommerce Cross-Site Request Forgery (1.3.2)