CVE-2025-68508: WordPress Brave plugin <= 0.8.3 - Broken Access Control vulnerability
Published Dec 24, 2025
·Updated
Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3.
Affected Software
2 affected components
Brave Brave<=0.8.3
npm/brave-plugin<=0.8.3
Event History
Dec 24, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Jan 12, 58291
Event
via MITRE·05:18 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-68508?
CVE-2025-68508 is classified as a missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2025-68508?
To fix CVE-2025-68508, upgrade the Brave Brave software or npm/brave-plugin to version greater than 0.8.3.
3
Which versions are affected by CVE-2025-68508?
CVE-2025-68508 affects Brave Brave versions from n/a through 0.8.3 and npm/brave-plugin up to 0.8.3.
4
What kind of impact can CVE-2025-68508 have?
CVE-2025-68508 can potentially allow unauthorized users to exploit incorrectly configured access controls.
5
Is CVE-2025-68508 specifically related to any particular feature?
CVE-2025-68508 is specifically related to the brave-popup-builder component within the Brave software.