CVE-2025-14799 | Brevo Plugin up to 3.3.0 on WordPress REST API Endpoint mailin_disconnect ID authorization
A vulnerability classified as critical was found in Brevo Plugin up to 3.3.0 on WordPress. The impacted element is an unknown function of the file /wp-json/mailin/v1/mailin_disconnect of the component REST API Endpoint. Such manipulation of the argument ID leads to authorization bypass.
This vulnerability is referenced as CVE-2025-14799. It is possible to launch the attack remotely. No exploit is available.