CVE-2024-8477
The Brevo plugin for WordPress, used for newsletters and email marketing, contains a security flaw in versions up to 3.1.87 that allows malicious actors to exploit Cross-Site Request Forgery vulnerabilities. This occurs because the Init() function fails to properly verify authentication tokens, enabling attackers to simulate legitimate actions without authorization. As a result, site administrators can be tricked into inadvertently logging out of their Brevo connections by clicking on a manipulated link.
Based on public CVE data (MITRE/NVD).