CVE · Medium

CVE-2024-8477 — Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8477 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.1.88 3.1.88 2024-10-09

CVE-2024-8477

The Brevo plugin for WordPress, used for newsletters and email marketing, contains a security flaw in versions up to 3.1.87 that allows malicious actors to exploit Cross-Site Request Forgery vulnerabilities. This occurs because the Init() function fails to properly verify authentication tokens, enabling attackers to simulate legitimate actions without authorization. As a result, site administrators can be tricked into inadvertently logging out of their Brevo connections by clicking on a manipulated link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.