Brave Popup Builder(插件名称/slug:brave-popup-builder)在 0.8.5 及更早版本中存在一个访问控制缺陷。任何已登录的用户(包括订阅者或 WooCommerce 客户),只需通过 URL 传递帖子 ID,即可访问其无权查看的弹窗内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77115 | Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters | |
| CVE-2026-77003 | Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_conten | |
| CVE-2026-14853 | WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Aut | |
| CVE-2026-13598 | RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator |
No comments yet