CVE · Medium

CVE-2021-24874 — Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24874 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.31 3.1.31 2022-01-12

CVE-2021-24874

The Brevo plugin versions prior to 3.1.31 contain reflected cross-site scripting vulnerabilities in the lang and pid parameters, which are output into HTML attributes without proper sanitization or escaping. An attacker could craft a malicious URL containing JavaScript code in these parameters to execute arbitrary scripts in a user's browser when they visit the link. This vulnerability affects the plugin's newsletter, SMTP, email marketing, and subscription form functionality.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.