Executive brief
The Brevo plugin for WordPress, which is used to manage email marketing and subscription forms, contains a security flaw that allows attackers to run malicious scripts in a user's browser. To exploit this, an attacker must trick a site visitor or administrator into clicking a specially crafted link. If successful, the attacker could potentially steal session information or perform unauthorized actions on behalf of the victim.
Technical details
The Brevo (formerly Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'page' parameter within the inc/table-forms.php file. An unauthenticated attacker can exploit this by crafting a malicious URL containing a script payload and persuading a target user (such as an administrator) to visit the link. The script then executes within the context of the victim's browser session. This vulnerability affects all versions up to and including 3.1.77; a patch was introduced in subsequent updates.
Affected products
- Brevo (formerly Sendinblue) Brevo – Email, SMS, Web Push, Chat, and more. Up to, and including, 3.1.77
Timeline
- 2026-07-10: advisory: NVD publication date
- 2026-07-10: disclosed: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/mailin/trunk/inc/table-forms.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3055756%40mailin%2Ftrunk&old=3032712%40mailin%2Ftrunk&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bf4cb79e-e62b-4991-8ee5-493dafe38b80?source=cve