PLUGIN SECURITY
Is Brave Popup Builder safe?
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
What this plugin does
- Slug:
brave-popup-builder - Author: Brave
- 20000+ active installs
- 96/100 rating (209 reviews on wordpress.org)
- 577359 all-time downloads
- On WordPress.org since 2019-11-30
lead generationpopuppopupswoocommerce popupwordpress popup
Maintenance status
- Latest known version: 0.8.7
- Last updated: 2026-08-06 1:19pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.2.24+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
7 known CVEs on file for Brave Popup Builder. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-77116 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.8.6 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 0.8.6 | 0.8.6 | 2026-08-23 | ✓ fixed in latest |
| CVE-2026-77115 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.8.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 0.8.6 | 0.8.6 | 2026-08-23 | ✓ fixed in latest |
| CVE-2025-68508 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.8.4 | Missing Authorization | Medium 5.3 | < 0.8.4 | 0.8.4 | 2025-12-23 | ✓ fixed in latest |
| CVE-2024-43337 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.7.1 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 0.7.1 | 0.7.1 | 2024-08-16 | ✓ fixed in latest |
| CVE-2024-35655 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 0.7.0 | 0.7.0 | 2024-06-03 | ✓ fixed in latest |
| CVE-2024-30453 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.6.6 | Server-Side Request Forgery (SSRF) | Medium 5.4 | < 0.6.6 | 0.6.6 | 2024-03-28 | ✓ fixed in latest |
| CVE-2023-51534 | Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 0.6.3 | 0.6.3 | 2023-12-27 | ✓ fixed in latest |
How to fix it
Keep Brave Popup Builder updated — 0.8.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Hostinger Reach – AI-Powered Email Marketing for WordPress — 1000000+ active installs — 100/100 (6) — max PHP 8.4
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation — 1000000+ active installs — 86/100 (815) — max PHP 8.4
- Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder — 700000+ active installs — 98/100 (4503) — max PHP 8.4
- CartFlows – Funnel Builder & Checkout Plugin for WooCommerce — 200000+ active installs — 96/100 (504) — max PHP 8.4
- Popup Builder – Create highly converting, mobile friendly marketing popups. — 200000+ active installs — 94/100 (2213)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.