plugin

Mailin Vulnerabilities

21 known security issues reported for the Mailin WordPress plugin. Most recent disclosed Feb 18, 2026.

1 high 8 medium

Running Mailin on your site? Check whether your installed version is affected.

Scan your site free

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1

unknown

[en] The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose comparison (==) instead of strict comparison (===) when validating the installation ID in the `/wp-json/mail...

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Feb 18, 2026

CVE-2025-14799 on NVD →

Brevo - Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Juggling

medium

The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose comparison (==) instead of strict comparison (===) when validating the installation ID in the `/wp-json/mailin/v1...

CVSS:
6.5
Affected:
up to 3.3.0
Fixed in:
3.3.1
Disclosed:
Feb 17, 2026

CVE-2025-14799 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88

unknown

[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthentica...

Affected:
up to 3.1.88
Fixed in:
3.1.88
Disclosed:
Oct 10, 2024

CVE-2024-8477 on NVD →

Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cross-Site Request Forgery

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthenticated a...

CVSS:
4.3
Affected:
up to 3.1.87
Fixed in:
3.1.88
Disclosed:
Oct 9, 2024

CVE-2024-8477 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.83

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.

Affected:
up to 3.1.83
Fixed in:
3.1.83
Disclosed:
Aug 26, 2024

CVE-2024-43287 on NVD →

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.82 - Cross-Site Request Forgery

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.82. This is due to missing or incorrect nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attack...

CVSS:
4.3
Affected:
up to 3.1.82
Fixed in:
3.1.83
Disclosed:
Aug 16, 2024

CVE-2024-43287 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77...

Affected:
up to 3.1.78
Fixed in:
3.1.78
Disclosed:
Jun 4, 2024

CVE-2024-35668 on NVD →

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.77 - Reflected Cross-Site Scripting

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

CVSS:
6.1
Affected:
up to 3.1.77
Fixed in:
3.1.78
Disclosed:
Jun 3, 2024

CVE-2024-35668 on NVD →

Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...

CVSS:
6.1
Affected:
up to 3.1.77
Fixed in:
3.1.78
Disclosed:
Mar 22, 2024

CVE-2026-15297 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78

unknown

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...

Affected:
up to 3.1.78
Fixed in:
3.1.78
Disclosed:
Mar 22, 2024

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61

unknown

[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used agains...

Affected:
up to 3.1.61
Fixed in:
3.1.61
Disclosed:
Jun 5, 2023

CVE-2023-2472 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61

unknown

Update the WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin to the latest available version (at least 3.1.61). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin. This c...

Affected:
up to 3.1.61
Fixed in:
3.1.61
Disclosed:
May 11, 2023

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.60 - Reflected Cross-Site Scripting via 'lang'

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in versions up to, and including, 3.1.60 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

CVSS:
6.1
Affected:
up to 3.1.60
Fixed in:
3.1.61
Disclosed:
May 10, 2023

CVE-2023-2472 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61

unknown

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in versions up to, and including, 3.1.60 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

Affected:
up to 3.1.61
Fixed in:
3.1.61
Disclosed:
May 10, 2023

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.39 - Cross-Site Scripting

high

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Scripting via many parameters in versions up to, and including, 3.1.39.

CVSS:
7.2
Affected:
up to 3.1.39
Fixed in:
3.1.40
Disclosed:
Apr 8, 2022

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.40

unknown

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Scripting via many parameters in versions up to, and including, 3.1.39.

Affected:
up to 3.1.40
Fixed in:
3.1.40
Disclosed:
Apr 8, 2022

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31

unknown

[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Affected:
up to 3.1.31
Fixed in:
3.1.31
Disclosed:
Feb 14, 2022

CVE-2021-24874 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25

unknown

[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Jan 24, 2022

CVE-2021-24923 on NVD →

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.30 - Reflected Cross-Site Scripting via lang & pid Parameters

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 3.1.31
Fixed in:
3.1.31
Disclosed:
Jan 12, 2022

CVE-2021-24874 on NVD →

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.24 - Reflected Cross-Site Scripting

medium

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Dec 23, 2021

CVE-2021-24923 on NVD →

Brevo &#8211; Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin (versions <= 3.1.24).

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Dec 22, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database