CVE · Medium

CVE-2024-30453 — Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-30453 Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.6.6 Server-Side Request Forgery (SSRF) Medium 5.4 < 0.6.6 0.6.6 2024-03-28

CVE-2024-30453

The Brave Popup Builder plugin for WordPress versions before 0.6.6 contains a server-side request forgery vulnerability that was discovered by Majed Refaea. An attacker could exploit this flaw to make the affected website send HTTP requests to arbitrary domains, potentially exposing sensitive information from internal services or other systems accessible to the server. The issue has been remediated in version 0.6.6 and all users should upgrade immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.