CVE-2026-77116 PUBLISHED

Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview

Assigner: WPScan
Reserved: 20.08.2026 Published: 23.08.2026 Updated: 23.08.2026

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.

Product Status

Vendor Unknown
Product Brave
Versions Default: unaffected
  • affected from 0 to 0.8.6 (excl.)

Credits

  • Huseyin Mertoglu finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE