Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
CVE-2026-77116
NONE
EPSS 0.18%
Updated Aug 23, 2026
Unknown
unknown:brave
CVE Details
CVE ID
CVE-2026-77116
Published Date
Aug 23, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
7.9th percentile (higher than 7.9% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory