CVE-2026-77116 - Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview
CVE ID :CVE-2026-77116
Published : Aug. 23, 2026, 6:17 a.m. | 2 hours, 10 minutes ago
Description :Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 23, 2026, 6:17 a.m. | 2 hours, 10 minutes ago
Description :Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...