CVE-2021-24923: Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.25 - Reflected XSS
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24923?
CVE-2021-24923 is classified as a high-severity vulnerability due to its potential for Reflected Cross-Site Scripting attacks.
How do I fix CVE-2021-24923?
To fix CVE-2021-24923, update the Sendinblue WordPress plugin to version 3.1.25 or later.
What systems are affected by CVE-2021-24923?
CVE-2021-24923 affects the Sendinblue and Brevo Newsletter, SMTP, Email marketing and Subscribe forms WordPress plugin versions before 3.1.25.
What impact does CVE-2021-24923 have?
CVE-2021-24923 allows attackers to execute arbitrary JavaScript in users' browsers, which can lead to data theft or session hijacking.
When was CVE-2021-24923 disclosed?
CVE-2021-24923 was disclosed in 2021, specifically highlighting vulnerabilities in earlier versions of the affected plugin.