Missing Authorization Vulnerability in Brevo Sendinblue for WooCommerce
CVE-2025-66128
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 December 2025
What is CVE-2025-66128?
A missing authorization vulnerability exists in the Brevo Sendinblue plugin for WooCommerce, affecting versions up to 4.0.49. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially enabling unauthorized access to sensitive functionality. Users should ensure proper access control configurations to mitigate the risks associated with this vulnerability.
Affected Version(s)
Sendinblue for WooCommerce 0 <= 4.0.49