WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content

The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …

6Reported vulnerabilities
7.2Highest CVSS score
0.8.7Latest version
20,000+Active installs

What to do now

Update Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content to 0.8.6 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 6, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-30453 High 7.2 0.3% 0.6.5 and earlier 0.6.6 March 28, 2024
CVE-2026-77115 Medium 6.1 0.1% Before 0.8.6 0.8.6 August 21, 2026
CVE-2025-68508 Medium 5.3 0.2% 0.8.3 and earlier 0.8.4 December 23, 2025
CVE-2024-35655 Medium 4.4 0.3% 0.6.9 and earlier 0.7.0 June 3, 2024
CVE-2023-51534 Medium 4.4 0.3% 0.6.2 and earlier 0.6.3 December 27, 2023
CVE-2024-43337 Medium 4.3 0.2% 0.7.0 and earlier 0.7.1 August 16, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.