CVE-2023-2472: Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.61 - Reflected XSS
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2472?
CVE-2023-2472 is classified as a critical vulnerability due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2023-2472?
To fix CVE-2023-2472, update the Sendinblue WordPress plugin to version 3.1.61 or later.
What software is affected by CVE-2023-2472?
CVE-2023-2472 affects the Sendinblue and Brevo Newsletter, SMTP, Email Marketing, and Subscribe WordPress plugins prior to version 3.1.61.
What type of vulnerability is CVE-2023-2472?
CVE-2023-2472 is a reflected cross-site scripting (XSS) vulnerability.
Is CVE-2023-2472 fixed in any specific plugin versions?
Yes, CVE-2023-2472 is addressed in versions 3.1.61 and newer of the affected plugins.