
Stored XSS in Brevo for WooCommerce | CVE-2025-14436 POC → 1. In the Brevo for WooCommerce WordPress plugin, the user_connection_id parameter was improperly sanitized 2. An attacker injected malicious HTML/JS into that field 3. The input was stored in the database 4. When any user (including admins) visited the impacted page, the script executed 5. This could allow credential theft, session hijacking, or unauthorized actions 6. Because no authentication was required, any visitor could trigger the exploit Learning → - Stored XSS is especially dangerous in plugins because it affects every visitor - Always sanitize + escape output on server side - WordPress plugins must validate all user input rigorously #bugbounty #bugbountytips #infosec #hacking #viehgroup #hacker
Post summary
The post discloses a stored XSS vulnerability (CVE‑2025‑14436) in the Brevo for WooCommerce WordPress plugin, provides a step‑by‑step proof of concept, and highlights potential impacts such as credential theft.
