SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15297

MEDIUM · CVSS 6.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The Brevo plugin for WordPress is susceptible to reflected cross-site scripting due to inadequate input sanitization and output escaping in the page parameter, affecting all versions up to 3.1.77. This vulnerability allows unauthenticated attackers to execute arbitrary scripts on user pages, potentially leading to session hijacking or data theft if users are manipulated into clicking malicious links. WordPress site administrators using this plugin should prioritize patching or updating to mitigate the risk.

CVE
CVE-2026-15297
Severity
MEDIUM
CVSS
6.1
EPSS
0.26%
WordPress

Original NVD Description

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.