CVE-2025-68508
9.1Brave · Brave Popup Builder
A missing authorization vulnerability in the Brave Popup Builder WordPress plugin allows unauthenticated attackers to exploit incorrectly configured access control settings.
Executive summary
A critical missing authorization vulnerability in the Brave Popup Builder plugin allows unauthenticated attackers to potentially bypass security controls.
Vulnerability
This is a CWE-862 Missing Authorization flaw occurring due to improper access control configuration. The CVSS vector (PR:N) confirms that the vulnerability is exploitable by unauthenticated attackers, making it significantly more dangerous than the other identified issues.
Business impact
The vulnerability allows for unauthenticated exploitation, which poses a severe risk to the confidentiality and integrity of the affected WordPress site. An attacker could potentially manipulate popup content or lead generation data, leading to unauthorized information disclosure or site defacement.
Remediation
Immediate Action: Update the Brave Popup Builder plugin to version 0.8.4 or later immediately.
Proactive Monitoring: Monitor for unusual activity or unauthorized configuration changes within the Brave plugin interface.
Compensating Controls: Implement strict WAF rules to block access to unauthorized plugin endpoints and monitor for anomalous traffic patterns directed at the plugin's directory.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability requires immediate attention due to the lack of required authentication for exploitation. Administrators must apply the version 0.8.4 update across all instances to prevent potential unauthorized access to site functionality.