
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-81571 is an unauthenticated arbitrary shortcode execution vulnerability in the Brave Popup Builder WordPress plugin affecting all versions before 0.8.8. The flaw allows unauthenticated remote attackers to execute arbitrary shortcodes registered on the target WordPress site server-side by manipulating a URL parameter intended to pre-fill form fields. It was publicly disclosed on August 31, 2026, and assigned a CVSS v3.1 base score of 4.8 (Medium) (WPScan, Github Advisory). The vulnerability was discovered and reported by Erwan LR of WPScan (WPScan).
The root cause is improper neutralization of special elements passed to a downstream component (CWE-74): the plugin fails to sanitize a URL parameter (such as a UTM parameter) used to pre-fill hidden form fields before passing it to WordPress's do_shortcode() engine (WPScan, Github Advisory). An attacker can craft a URL containing a shortcode payload in the relevant parameter, which the plugin then passes directly to the WordPress shortcode engine for server-side execution. Exploitation requires the target site to have published a popup containing a hidden form field configured to take its default value from a URL parameter, making this a high-complexity attack (AC:H). A proof-of-concept is scheduled for public release on September 14, 2026, to allow time for users to update (WPScan).
Successful exploitation allows an unauthenticated attacker to execute any shortcode registered on the WordPress site server-side, with the privileges of the WordPress application. This can lead to limited confidentiality and integrity impacts depending on what shortcodes are registered — for example, shortcodes that expose sensitive data or modify site content could be abused. Availability is not directly impacted, but chained with powerful third-party shortcodes, the effective impact could exceed the base CVSS score (WPScan, Github Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (WPScan). The EPSS score is 0.0, reflecting a very low current probability of exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable due to the high attack complexity precondition requiring a specific site configuration.
utm_source).https://target.com/page/?utm_source=[shortcode_here]).do_shortcode() function, executing the injected shortcode server-side.[, ]) in URL parameters such as utm_source, utm_medium, or other pre-fill parameters.Update the Brave Popup Builder WordPress plugin to version 0.8.8 or later, which addresses the unsanitized URL parameter issue (WPScan). As a temporary workaround prior to patching, consider implementing Web Application Firewall (WAF) rules to detect and block requests containing shortcode syntax (e.g., [ and ] characters) in URL parameters. Additionally, review and minimize the number of powerful shortcodes registered on the site to reduce the potential impact of exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."