CVE-2023-2472 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Sendinblue WordPress plugin versions prior to 3.1.61, specifically when the WPML plugin is also active and configured. The vulnerability stems from insufficient sanitization of a parameter in the admin dashboard. It carries a CVSS score of 6.1 (Medium), indicating a low complexity attack that requires user interaction and could lead to information disclosure and integrity compromise for high-privilege users. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.61CPE matchmatch criteria | cpe:2.3:a:brevo:newsletter\,_smtp\,_email_marketing_and_subscribe:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.