Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1
unknown
[en] The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose comparison (==) instead of strict comparison (===) when validating the installation ID in the `/wp-json/mail...
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Feb 18, 2026
CVE-2025-14799 on NVD →
Brevo - Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Juggling
medium
The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose comparison (==) instead of strict comparison (===) when validating the installation ID in the `/wp-json/mailin/v1...
- CVSS:
- 6.5
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.1
- Disclosed:
- Feb 17, 2026
CVE-2025-14799 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88
unknown
[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthentica...
- Affected:
- up to 3.1.88
- Fixed in:
- 3.1.88
- Disclosed:
- Oct 10, 2024
CVE-2024-8477 on NVD →
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cross-Site Request Forgery
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthenticated a...
- CVSS:
- 4.3
- Affected:
- up to 3.1.87
- Fixed in:
- 3.1.88
- Disclosed:
- Oct 9, 2024
CVE-2024-8477 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.83
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.
- Affected:
- up to 3.1.83
- Fixed in:
- 3.1.83
- Disclosed:
- Aug 26, 2024
CVE-2024-43287 on NVD →
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.82 - Cross-Site Request Forgery
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.82. This is due to missing or incorrect nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attack...
- CVSS:
- 4.3
- Affected:
- up to 3.1.82
- Fixed in:
- 3.1.83
- Disclosed:
- Aug 16, 2024
CVE-2024-43287 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77...
- Affected:
- up to 3.1.78
- Fixed in:
- 3.1.78
- Disclosed:
- Jun 4, 2024
CVE-2024-35668 on NVD →
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.77 - Reflected Cross-Site Scripting
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- CVSS:
- 6.1
- Affected:
- up to 3.1.77
- Fixed in:
- 3.1.78
- Disclosed:
- Jun 3, 2024
CVE-2024-35668 on NVD →
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...
- CVSS:
- 6.1
- Affected:
- up to 3.1.77
- Fixed in:
- 3.1.78
- Disclosed:
- Mar 22, 2024
CVE-2026-15297 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78
unknown
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...
- Affected:
- up to 3.1.78
- Fixed in:
- 3.1.78
- Disclosed:
- Mar 22, 2024
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61
unknown
[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used agains...
- Affected:
- up to 3.1.61
- Fixed in:
- 3.1.61
- Disclosed:
- Jun 5, 2023
CVE-2023-2472 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61
unknown
Update the WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin to the latest available version (at least 3.1.61).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin. This c...
- Affected:
- up to 3.1.61
- Fixed in:
- 3.1.61
- Disclosed:
- May 11, 2023
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.60 - Reflected Cross-Site Scripting via 'lang'
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in versions up to, and including, 3.1.60 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...
- CVSS:
- 6.1
- Affected:
- up to 3.1.60
- Fixed in:
- 3.1.61
- Disclosed:
- May 10, 2023
CVE-2023-2472 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61
unknown
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in versions up to, and including, 3.1.60 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...
- Affected:
- up to 3.1.61
- Fixed in:
- 3.1.61
- Disclosed:
- May 10, 2023
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.39 - Cross-Site Scripting
high
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Scripting via many parameters in versions up to, and including, 3.1.39.
- CVSS:
- 7.2
- Affected:
- up to 3.1.39
- Fixed in:
- 3.1.40
- Disclosed:
- Apr 8, 2022
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.40
unknown
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Scripting via many parameters in versions up to, and including, 3.1.39.
- Affected:
- up to 3.1.40
- Fixed in:
- 3.1.40
- Disclosed:
- Apr 8, 2022
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31
unknown
[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.31
- Disclosed:
- Feb 14, 2022
CVE-2021-24874 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25
unknown
[en] The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Jan 24, 2022
CVE-2021-24923 on NVD →
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.30 - Reflected Cross-Site Scripting via lang & pid Parameters
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.31
- Disclosed:
- Jan 12, 2022
CVE-2021-24874 on NVD →
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.24 - Reflected Cross-Site Scripting
medium
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Dec 23, 2021
CVE-2021-24923 on NVD →
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin (versions <= 3.1.24).
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Dec 22, 2021