Brevo · Newsletters · CVE-2026-15297
**Name of the Vulnerable Software and Affected Versions**
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress versions prior to 3.1.78
**Description**
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting (XSS), a technique where malicious scripts are injected into a web page and executed in the victim's browser. This occurs via the `page` parameter, enabling the execution of arbitrary web scripts if a user is tricked into clicking a malicious link.
**Recommendations**
Update the plugin to version 3.1.78 or later.
As a temporary mitigation, restrict or sanitize the use of the `page` parameter.