Executive brief
Brave Conversion Engine (PRO) is a WordPress plugin used to create popups and forms for lead generation and user engagement. An unauthenticated attacker can inject malicious scripts into affected websites, allowing them to steal visitor data, hijack user accounts, or deface content without requiring any special permissions.
Technical details
A reflected or stored cross-site scripting (XSS) vulnerability exists in Brave Conversion Engine (PRO) versions 0.8.6 and earlier due to insufficient input validation or output encoding. The vulnerability is unauthenticated and requires user interaction (e.g., clicking a malicious link or visiting a crafted page) to be exploited. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser, enabling theft of sensitive data, session hijacking, or malware distribution. The vulnerability is patched in version 0.8.7 and later.
Affected products
- Brave Conversion Engine (PRO) <= 0.8.6
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: patch released in version 0.8.7