CVE-2026-77116: Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
brave-popup-builderto a version that resolves this vulnerability.Fixed in 0.8.6
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with Subscriber-level access or a WooCommerce Customer account can exploit it. The attacker does not need administrative or editor privileges.
What does an attacker need to access unpublished popup content?
They need to be logged in and able to supply the ID of the target popup in the preview URL. The issue exposes popup content that the user would not normally be authorized to read.
Which versions are affected?
Brave Popup Builder versions through 0.8.5 are affected. Version 0.8.6 is the first version identified as not affected.