CVE · Medium

CVE-2025-68508 — Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.8.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-68508 Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.8.4 Missing Authorization Medium 5.3 < 0.8.4 0.8.4 2025-12-23

CVE-2025-68508

A critical security flaw exists in the Brave – Create Popup plugin for WordPress, affecting all versions up to 0.8.3. The issue arises from a failure to verify user permissions when executing a specific function, allowing malicious actors without authentication to carry out unauthorized operations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.