CVE-2026-77115
7.1Brave · Popup Builder
A reflected cross-site scripting (XSS) vulnerability in the Brave Popup Builder plugin allows unauthenticated attackers to execute arbitrary scripts in the context of a user session.
Executive summary
A reflected cross-site scripting vulnerability in Brave Popup Builder allows unauthenticated attackers to execute malicious scripts, posing a significant risk to user session security.
Vulnerability
The plugin suffers from a reflected cross-site scripting vulnerability. This flaw allows an unauthenticated attacker to inject malicious scripts into web pages viewed by other users.
Business impact
Exploitation of this XSS vulnerability can lead to session hijacking, unauthorized actions on behalf of administrators, or the theft of sensitive user data. With a CVSS score of 7.1, the risk is elevated because it can be used to compromise the integrity of the administrative interface.
Remediation
Immediate Action: Update the Brave Popup Builder plugin to version 0.8.6 or later immediately.
Proactive Monitoring: Review web server logs for suspicious URL parameters containing script tags or encoded malicious payloads.
Compensating Controls: Ensure that a robust Content Security Policy (CSP) is in place to restrict the execution of unauthorized scripts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
All users of the Brave Popup Builder plugin must update to version 0.8.6 to resolve this security flaw. Failure to patch allows for potential script injection attacks that can undermine the security of the entire WordPress environment.