PT-2026-79763 · WordPress · Brave Popup Builder
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brave Popup Builder versions prior to 0.8.6
Description
Brave Popup Builder contains a broken access control issue. Any authenticated user, including those with Subscriber or WooCommerce Customer roles, can access and read popup content they are not authorized to view by providing a post ID within the URL.
Recommendations
Update Brave Popup Builder to version 0.8.6 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brave Popup Builder