CVE-2026-81571: Brave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution via UTM Parameter
The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have arbitrary shortcodes registered on the site executed server-side.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
WordPress sites using the Brave Popup Builder plugin at a version earlier than 0.8.8 are affected. Exploitation requires that the site has shortcodes registered that produce security-relevant behavior when executed.
Does an attacker need an account or user interaction to exploit it?
No. The issue is described as unauthenticated and can be triggered through a URL parameter used to pre-fill a form field, so an attacker does not need a WordPress account or victim interaction.
What is the immediate remediation?
Update Brave Popup Builder to version 0.8.8 or later. The provided data does not identify a workaround for installations that cannot be patched immediately.