Executive brief
Brave Popup Builder is a WordPress plugin that creates promotional and marketing popups on websites. A flaw in the preview feature allows any logged-in user—even with minimal Subscriber permissions—to view draft, pending, private, and scheduled popup content they shouldn't have access to by manipulating the URL. This could expose unreleased campaigns, coupon codes, integration endpoints, and other sensitive marketing data intended for future or restricted use.
Technical details
The vulnerability is an IDOR (Insecure Direct Object Reference) / broken object-level access control issue in the bravepop_render_popup() function in lib/render.php. The preview feature checks only is_user_logged_in() when the brave_popup query parameter is present, performing no capability check, post status validation, or object ownership verification. An authenticated Subscriber or WooCommerce Customer can supply any popup post ID in the URL and retrieve rendered content regardless of post status (draft, pending, private, scheduled) or audience targeting rules. The vulnerability is a separate code path from the previously fixed CVE-2025-68508 (patched in 0.8.4), which affected an unauthenticated AJAX handler. This GET preview branch requires authentication but lacks the capability gates added to that handler. Fixed in version 0.8.6.
Affected products
- Brave Popup Builder through 0.8.5
Timeline
- 2026-08-23: disclosed
- 2026-08-23: patched: Fixed in version 0.8.6