CyberRota Analysis
AI-GeneratedBrave Popup Builder versions up to 0.8.5 are vulnerable to a broken access control issue, allowing any logged-in user, including Subscribers and WooCommerce Customers, to access restricted popup content by manipulating the post ID in the URL. This vulnerability could lead to unauthorized information disclosure, potentially exposing sensitive data. Organizations using this plugin should prioritize remediation to safeguard user data and maintain compliance with access control policies.
Original NVD Description
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.