PT-2026-84747 · WordPress · Brave
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Brave WordPress plugin versions prior to 0.8.8
Description
An issue exists where a URL parameter used to pre-fill a form field is not properly sanitized before being passed to the WordPress shortcode engine. This allows unauthenticated attackers to execute arbitrary shortcodes registered on the site server-side.
Recommendations
Update the Brave WordPress plugin to version 0.8.8 or later.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brave