SendGrid for WordPress <= 1.4 - Missing Authorization
EntreBase Advisory: The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Read more about this vulnerability: https://www.wordfence.com/threat-intel/vulnerabilities/id/3fa9e1cf-a7d5-4373-81ca-87e9275fe413?source=api-prod