Executive brief
Brave Popup Builder is a WordPress plugin used to create and display popup campaigns on websites. The plugin fails to properly escape user-supplied UTM tracking parameters before displaying them in popup form fields, allowing attackers to inject malicious code that executes in visitors' browsers without requiring any authentication or action beyond opening a crafted link. This could lead to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw (CWE-79) affecting Brave Popup Builder versions up to 0.8.5. When a popup form is configured with fields that use "UTM Parameter" as the default value source, the plugin directly reflects the corresponding $_GET parameter into the HTML output without applying any escaping functions (esc_attr, esc_html, esc_textarea). The vulnerable code is located in lib/frontend/Form.php in the renderInput() (line 408), renderHidden() (lines 442-456), and renderTextarea() (lines 475-484) functions. An unauthenticated attacker can craft a malicious URL with injected HTML/JavaScript in UTM parameters (e.g., utm_source, utm_medium, utm_campaign) and send it to victims; when the page containing the popup loads, the payload executes in the victim's browser context regardless of session state. The vulnerability was fixed in version 0.8.6 by properly entity-encoding reflected values.
Affected products
- Brave Popup Builder up to 0.8.5
Timeline
- 2026-08-21: disclosed
- 2026-08-23: patched: Fixed in version 0.8.6