CVE-2025-14436PoC

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’ parameter in all versions up to, and including, 4.0.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-11: 1Technical Details · 2026-02-11: 102-11
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • VIEH Group@viehgroup
    PoC

    Stored XSS in Brevo for WooCommerce | CVE-2025-14436 POC → 1. In the Brevo for WooCommerce WordPress plugin, the user_connection_id parameter was improperly sanitized 2. An attacker injected malicious HTML/JS into that field 3. The input was stored in the database 4. When any user (including admins) visited the impacted page, the script executed 5. This could allow credential theft, session hijacking, or unauthorized actions 6. Because no authentication was required, any visitor could trigger the exploit Learning → - Stored XSS is especially dangerous in plugins because it affects every visitor - Always sanitize + escape output on server side - WordPress plugins must validate all user input rigorously #bugbounty #bugbountytips #infosec #hacking #viehgroup #hacker

    Post summary

    The post discloses a stored XSS vulnerability (CVE‑2025‑14436) in the Brevo for WooCommerce WordPress plugin, provides a step‑by‑step proof of concept, and highlights potential impacts such as credential theft.

    100104892
    5.9K followersView on X

Explore more