PT-2026-79762 · WordPress · Brave Popup Builder
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Brave Popup Builder versions prior to 0.8.6
Description
Brave Popup Builder reflects UTM query parameters into the popup form HTML without proper escaping, leading to Reflected Cross-Site Scripting (XSS). This occurs when the application takes user-supplied input from UTM parameters and includes it in the HTML response without sanitization.
Recommendations
Update Brave Popup Builder to version 0.8.6 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brave Popup Builder