Access Flaw in WordPress Plugin Exposes Restricted Popup Content

Access Flaw in WordPress Plugin Exposes Restricted Popup Content

First seen 25 Aug 2026, 05:20 UTC Ciberseguridadlatam 45.8

Article Content

Browse articles
ThreatCluster

A vulnerability identified as CVE-2026-77116 affects the Brave Popup Builder plugin for WordPress, allowing unauthorized access to restricted popup content by users with minimal permissions, such as subscribers and customers. This flaw is present in versions up to 0.8.5 of the plugin. The issue arises from broken access control, which can lead to sensitive information exposure on affected websites. The vulnerability was published on August 23, 2026, and affects any site utilizing the vulnerable plugin. Users are advised to update to the latest version to mitigate risks. There are no reports of active exploitation at this time, but the potential for misuse exists.

Key Points: • CVE-2026-77116 allows unauthorized access to popup content. • Affected versions of Brave Popup Builder are up to 0.8.5. • No active exploitation has been reported yet.

Timeline

2026-08-23
CVE-2026-77116 published
The vulnerability in Brave Popup Builder was officially disclosed, affecting versions up to 0.8.5.
Ciberseguridadlatam
2026-08-25
Vulnerability reported
Ciberseguridadlatam published details about the access flaw, emphasizing the need for immediate updates.
Ciberseguridadlatam