SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77116

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-23 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Brave Popup Builder versions up to 0.8.5 are vulnerable to a broken access control issue, allowing any logged-in user, including Subscribers and WooCommerce Customers, to access restricted popup content by manipulating the post ID in the URL. This vulnerability could lead to unauthorized information disclosure, potentially exposing sensitive data. Organizations using this plugin should prioritize remediation to safeguard user data and maintain compliance with access control policies.

CVE
CVE-2026-77116
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.