CVE-2025-68508

9.1

Brave · Brave Popup Builder

A missing authorization vulnerability in the Brave Popup Builder WordPress plugin allows unauthenticated attackers to exploit incorrectly configured access control settings.

Executive summary

A critical missing authorization vulnerability in the Brave Popup Builder plugin allows unauthenticated attackers to potentially bypass security controls.

Vulnerability

This is a CWE-862 Missing Authorization flaw occurring due to improper access control configuration. The CVSS vector (PR:N) confirms that the vulnerability is exploitable by unauthenticated attackers, making it significantly more dangerous than the other identified issues.

Business impact

The vulnerability allows for unauthenticated exploitation, which poses a severe risk to the confidentiality and integrity of the affected WordPress site. An attacker could potentially manipulate popup content or lead generation data, leading to unauthorized information disclosure or site defacement.

Remediation

Immediate Action: Update the Brave Popup Builder plugin to version 0.8.4 or later immediately.

Proactive Monitoring: Monitor for unusual activity or unauthorized configuration changes within the Brave plugin interface.

Compensating Controls: Implement strict WAF rules to block access to unauthorized plugin endpoints and monitor for anomalous traffic patterns directed at the plugin's directory.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability requires immediate attention due to the lack of required authentication for exploitation. Administrators must apply the version 0.8.4 update across all instances to prevent potential unauthorized access to site functionality.