Junglewise Threat Intelligence

CVE-2026-15297: Brevo WordPress plugin reflected XSS in page parameter

CVE-2026-15297 · Severity: medium · CVSS 6.1 · Published 2026-07-10

Executive brief

The Brevo plugin for WordPress, which is used to manage email marketing and subscription forms, contains a security flaw that allows attackers to run malicious scripts in a user's browser. To exploit this, an attacker must trick a site visitor or administrator into clicking a specially crafted link. If successful, the attacker could potentially steal session information or perform unauthorized actions on behalf of the victim.

Technical details

The Brevo (formerly Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'page' parameter within the inc/table-forms.php file. An unauthenticated attacker can exploit this by crafting a malicious URL containing a script payload and persuading a target user (such as an administrator) to visit the link. The script then executes within the context of the victim's browser session. This vulnerability affects all versions up to and including 3.1.77; a patch was introduced in subsequent updates.

Affected products

  • Brevo (formerly Sendinblue) Brevo – Email, SMS, Web Push, Chat, and more. Up to, and including, 3.1.77

Timeline

  • 2026-07-10: advisory: NVD publication date
  • 2026-07-10: disclosed: Wordfence advisory published

References