CVE-2026-77116
Received Received - Intake

Broken Access Control in Brave Popup Builder

Vulnerability report for CVE-2026-77116, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-23

Last updated on: 2026-08-23

Assigner: WPScan

Description

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough β€” can read popup content they shouldn't have access to by passing a post ID in the URL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-23
Last Modified
2026-08-23
Generated
2026-08-23
AI Q&A
2026-08-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brave popup_builder to 0.8.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Brave Popup Builder versions through 0.8.5 have an Insecure Direct Object Reference (IDOR) vulnerability. Any logged-in user, including Subscribers or WooCommerce Customers, can access unpublished popup content by modifying the URL with a post ID parameter. The vulnerability occurs in the bravepop_render_popup() function which does not verify user permissions or post status before displaying content.

Detection Guidance

Check if the Brave Popup Builder plugin version is 0.8.5 or lower. Inspect network traffic for requests containing the 'brave_popup' parameter in the URL. Look for unauthorized access to popup content by logged-in users with non-admin roles.

Impact Analysis

This vulnerability allows unauthorized users to view sensitive popup content such as draft campaigns, restricted promotions, coupon codes, or integration endpoints. Attackers can iterate through post IDs to access unpublished or protected popups, potentially exposing confidential information or unreleased marketing materials.

Compliance Impact

This vulnerability may lead to unauthorized access to sensitive data, which could violate GDPR (if personal data is exposed) or HIPAA (if health-related information is compromised). Organizations must ensure proper access controls to maintain compliance with data protection regulations.

Mitigation Strategies

Update the Brave Popup Builder plugin to version 0.8.6 or later immediately. Remove or restrict access for non-admin users to the 'brave_popup' parameter functionality. Review popup content permissions and ensure only authorized users can access unpublished or restricted popups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77116. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart