Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Mailin — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
mailin
- 100000+ instalaciones activas
brevoEmail Marketingformsnewslettersendinblue
Estado de mantenimiento
- Última versión conocida: 3.3.5
- Requiere PHP: 5.6+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
8 CVEs conocidos registrados para Mailin.
Reportadas entre 2021 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-15297
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.1.78
|
3.1.78 |
2026-07-10 |
✓ corregido en la última versión
|
|
CVE-2025-14799
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1 |
Acceso a un recurso usando un tipo incompatible (Type Confusion) |
Media
6,5
|
< 3.3.1
|
3.3.1 |
2026-02-17 |
✓ corregido en la última versión
|
|
CVE-2024-8477
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 3.1.88
|
3.1.88 |
2024-10-09 |
✓ corregido en la última versión
|
|
CVE-2024-43287
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.83 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
8,8
|
< 3.1.83
|
3.1.83 |
2024-08-16 |
✓ corregido en la última versión
|
|
CVE-2024-35668
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.1.78
|
3.1.78 |
2024-06-03 |
✓ corregido en la última versión
|
|
—
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 |
— |
Desconocido
|
< 3.1.78
|
3.1.78 |
2024-03-22 |
✓ corregido en la última versión
|
|
CVE-2023-2472
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.1.61
|
3.1.61 |
2023-06-05 |
✓ corregido en la última versión
|
|
—
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 |
— |
Desconocido
|
< 3.1.61
|
3.1.61 |
2023-05-11 |
✓ corregido en la última versión
|
CVE-2026-15297
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-14799
The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose comparison (==) instead of strict comparison (===) when validating the installation ID in the `/wp-json/mailin/v1/mailin_disconnect` REST API endpoint. This makes it possible for unauthenticated attackers to disconnect the Brevo integration, delete the API key, remove all subscription forms, and reset plugin settings by sending a boolean `true` value for the `id` parameter, which bypasses the authorization check through PHP type juggling.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-8477
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthenticated attackers to log out of a Brevo connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-43287
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.82. This is due to missing or incorrect nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to perform bulk actions on forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-35668
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-2472
Update the WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin to the latest available version (at least 3.1.61).
Erwan LR (WPScan) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.1.61.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61
Update the WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin to the latest available version (at least 3.1.61).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.1.61.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 5 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 |
— |
Desconocido
|
< 3.1.61
|
3.1.61 |
2023-05-10 |
✓ corregido en la última versión
|
|
—
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.40 |
— |
Desconocido
|
< 3.1.40
|
3.1.40 |
2022-04-08 |
✓ corregido en la última versión
|
|
CVE-2021-24874
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.1.31
|
3.1.31 |
2022-01-12 |
✓ corregido en la última versión
|
|
CVE-2021-24923
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.1.25
|
3.1.25 |
2021-12-23 |
✓ corregido en la última versión
|
|
—
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25 |
— |
Desconocido
|
< 3.1.25
|
3.1.25 |
2021-12-22 |
✓ corregido en la última versión
|
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in versions up to, and including, 3.1.60 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.40
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Scripting via many parameters in versions up to, and including, 3.1.39.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24874
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24923
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin (versions <= 3.1.24).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Mailin actualizado — 3.3.5 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas
-
Hostinger Reach – AI-Powered Email Marketing for WordPress
— 1000000+ instalaciones activas
— 100/100 (5)
— PHP máx. 8.4
-
MailPoet – Newsletters, Email Marketing, and Automation
— 500000+ instalaciones activas
— 88/100 (1423)
-
Newsletter – Send awesome emails from WordPress
— 200000+ instalaciones activas
— 92/100 (1203)
— PHP máx. 8.4
-
Newsletters, Email Marketing, SMS and Popups by Omnisend
— 100000+ instalaciones activas
— 96/100 (16)
— PHP máx. 8.4
-
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
— 80000+ instalaciones activas
— 96/100 (248)
— PHP máx. <8.0