Junglewise Threat Intelligence

CVE-2026-77115: Brave Popup Builder reflected XSS via UTM parameters

CVE-2026-77115 · Severity: high · CVSS 7.1 · Published 2026-08-23

Executive brief

Brave Popup Builder is a WordPress plugin used to create and display popup campaigns on websites. The plugin fails to properly escape user-supplied UTM tracking parameters before displaying them in popup form fields, allowing attackers to inject malicious code that executes in visitors' browsers without requiring any authentication or action beyond opening a crafted link. This could lead to session hijacking, credential theft, or malware distribution.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw (CWE-79) affecting Brave Popup Builder versions up to 0.8.5. When a popup form is configured with fields that use "UTM Parameter" as the default value source, the plugin directly reflects the corresponding $_GET parameter into the HTML output without applying any escaping functions (esc_attr, esc_html, esc_textarea). The vulnerable code is located in lib/frontend/Form.php in the renderInput() (line 408), renderHidden() (lines 442-456), and renderTextarea() (lines 475-484) functions. An unauthenticated attacker can craft a malicious URL with injected HTML/JavaScript in UTM parameters (e.g., utm_source, utm_medium, utm_campaign) and send it to victims; when the page containing the popup loads, the payload executes in the victim's browser context regardless of session state. The vulnerability was fixed in version 0.8.6 by properly entity-encoding reflected values.

Affected products

  • Brave Popup Builder up to 0.8.5

Timeline

  • 2026-08-21: disclosed
  • 2026-08-23: patched: Fixed in version 0.8.6

References