Impact
The Brevo WordPress plugin is vulnerable to a CWE-79 Reflected Cross‑Site Scripting flaw with a CVSS score of 6.1, indicating a moderate level of severity. The EPSS score of < 1% suggests a very low yet non‑zero probability of exploitation. Exploitation requires an unauthenticated attacker to trick a victim into clicking a crafted link; the flaw is not listed in the CISA KEV catalog, implying no known mass exploitation. If successful, the vulnerability could allow malicious scripts to run in the victim’s browser, potentially compromising the confidentiality and integrity of data entered into the affected forms.
Affected Systems
Brevo – Email, SMS, Web Push, Chat, and more WordPress plugin versions up to and including 3.1.77 are affected.
Risk and Exploitability
The moderate CVSS score of 6.1 indicates a moderate level of severity, and the EPSS score of < 1% reflects a very low but non‑zero likelihood of exploitation. Because the flaw is not listed in the CISA KEV catalog, there are no known large‑scale exploitation campaigns, but the vulnerability requires only an unauthenticated attacker to craft a link that triggers a click. A successful exploitation would allow arbitrary scripts to run in the victim’s browser, enabling theft or manipulation of data entered into the affected forms. The absence of a known exploit does not mitigate the risk of a targeted or opportunistic attack with this flaw.
OpenCVE Enrichment