PLUGIN SECURITY
Is Mailin safe?
Turn your WordPress site into a marketing powerhouse. Grow your audience, boost engagement, and drive more sales with Brevo.
What this plugin does
- Slug:
mailin - Author: Brevo
- 100000+ active installs
- 82/100 rating (285 reviews on wordpress.org)
- 7442347 all-time downloads
- On WordPress.org since 2012-09-06
brevoEmail Marketingformsnewslettersendinblue
Maintenance status
- Latest known version: 3.3.5
- Last updated: 2026-06-24 6:57am GMT
- Tested up to WordPress: 6.9.7
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
8 known CVEs on file for Mailin. Reported between 2021 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-14799 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1 | Access of Resource Using Incompatible Type ('Type Confusion') | Medium 6.5 | < 3.3.1 | 3.3.1 | 2026-02-17 | ✓ fixed in latest |
| CVE-2024-8477 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.88 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.1.88 | 3.1.88 | 2024-10-09 | ✓ fixed in latest |
| CVE-2024-43287 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.83 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 3.1.83 | 3.1.83 | 2024-08-16 | ✓ fixed in latest |
| CVE-2024-35668 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.78 | 3.1.78 | 2024-06-03 | ✓ fixed in latest |
| CVE-2026-15297 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.78 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.78 | 3.1.78 | 2024-03-22 | ✓ fixed in latest |
| — | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 | — | Unknown | < 3.1.61 | 3.1.61 | 2023-05-11 | ✓ fixed in latest |
| CVE-2023-2472 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.61 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.61 | 3.1.61 | 2023-05-10 | ✓ fixed in latest |
| — | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.40 | — | Unknown | < 3.1.40 | 3.1.40 | 2022-04-08 | ✓ fixed in latest |
+ 5 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2021-24874 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.31 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.31 | 3.1.31 | 2022-01-12 | ✓ fixed in latest |
| CVE-2021-24923 | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.25 | 3.1.25 | 2021-12-23 | ✓ fixed in latest |
| — | Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.1.25 | — | Unknown | < 3.1.25 | 3.1.25 | 2021-12-22 | ✓ fixed in latest |
| CVE-2023-2472 | Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.61 - Reflected XSS | — | Unknown | < 3.1.61 | 3.1.61 | — | ✓ fixed in latest |
| — | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo < 3.1.78 - Reflected XSS | — | Unknown | < 3.1.78 | 3.1.78 | — | ✓ fixed in latest |
How to fix it
Keep Mailin updated — 3.3.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Hostinger Reach – AI-Powered Email Marketing for WordPress — 1000000+ active installs — 100/100 (6) — max PHP 8.4
- MailPoet – Newsletters, Email Marketing, and Automation — 500000+ active installs — 88/100 (1431)
- Newsletter – Send awesome emails from WordPress — 200000+ active installs — 92/100 (1203) — max PHP 8.4
- Newsletters, Email Marketing, SMS and Popups by Omnisend — 100000+ active installs — 96/100 (16) — max PHP 8.4
- FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution — 80000+ active installs — 96/100 (249) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.