PLUGIN SECURITY

Is Mailin safe?

Turn your WordPress site into a marketing powerhouse. Grow your audience, boost engagement, and drive more sales with Brevo.

What this plugin does

  • Slug: mailin
  • Author: Brevo
  • 100000+ active installs
  • 82/100 rating (285 reviews on wordpress.org)
  • 7442347 all-time downloads
  • On WordPress.org since 2012-09-06

brevoEmail Marketingformsnewslettersendinblue

Maintenance status

  • Latest known version: 3.3.5
  • Last updated: 2026-06-24 6:57am GMT
  • Tested up to WordPress: 6.9.7
  • Requires PHP: 5.6+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

8 known CVEs on file for Mailin. Reported between 2021 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14799 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1 Access of Resource Using Incompatible Type ('Type Confusion') Medium 6.5 < 3.3.1 3.3.1 2026-02-17 ✓ fixed in latest
CVE-2024-8477 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.1.88 3.1.88 2024-10-09 ✓ fixed in latest
CVE-2024-43287 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.83 Cross-Site Request Forgery (CSRF) High 8.8 < 3.1.83 3.1.83 2024-08-16 ✓ fixed in latest
CVE-2024-35668 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.78 3.1.78 2024-06-03 ✓ fixed in latest
CVE-2026-15297 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.78 3.1.78 2024-03-22 ✓ fixed in latest
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 Unknown < 3.1.61 3.1.61 2023-05-11 ✓ fixed in latest
CVE-2023-2472 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.61 3.1.61 2023-05-10 ✓ fixed in latest
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.40 Unknown < 3.1.40 3.1.40 2022-04-08 ✓ fixed in latest
+ 5 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24874 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.31 3.1.31 2022-01-12 ✓ fixed in latest
CVE-2021-24923 Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.25 3.1.25 2021-12-23 ✓ fixed in latest
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25 Unknown < 3.1.25 3.1.25 2021-12-22 ✓ fixed in latest
CVE-2023-2472 Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.61 - Reflected XSS Unknown < 3.1.61 3.1.61 ✓ fixed in latest
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo < 3.1.78 - Reflected XSS Unknown < 3.1.78 3.1.78 ✓ fixed in latest

How to fix it

Keep Mailin updated — 3.3.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.