CVE-2024-43287: WordPress Brevo plugin <= 3.1.82 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43287?
The severity of CVE-2024-43287 is considered high due to its potential to allow unauthorized actions through cross-site request forgery.
How do I fix CVE-2024-43287?
To fix CVE-2024-43287, update the Sendinblue Newsletter, SMTP, Email Marketing, and Subscribe forms plugin to version 3.1.83 or later.
What versions are affected by CVE-2024-43287?
CVE-2024-43287 affects versions of the Sendinblue plugin prior to 3.1.83.
What is Cross-Site Request Forgery (CSRF) in the context of CVE-2024-43287?
Cross-Site Request Forgery (CSRF) in CVE-2024-43287 allows attackers to perform actions on behalf of an authenticated user without their consent.
What should I do if I'm using an affected version of the Sendinblue plugin related to CVE-2024-43287?
If using an affected version of the Sendinblue plugin, it is crucial to update to the latest version immediately to mitigate the CSRF vulnerability.