Impact
Brave’s popup‑builder plugin up to version 0.8.3 contains a missing authorization flaw that lets an attacker bypass the plugin’s access‑control checks. Without proper authentication, a user can reach privileged configuration pages and potentially alter or expose site content, thereby compromising confidentiality or integrity of the WordPress installation.
Affected Systems
WordPress websites that have the Brave popup‑builder plugin installed, any version up to 0.8.3. No specific WordPress core versions are listed, and only the plugin vendor Brave appears in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not in the CISA KEV catalog. Because it is a missing authorization bug, an attacker could exploit it remotely through web requests to the plugin’s admin area and gain unintended access without needing elevated privileges. The primary attack vector is therefore likely remote via HTTP.
OpenCVE Enrichment