PatchSiren

broadstreetads CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM broadstreetads CVE published 2026-05-21

CVE-2026-1881

CVE-2026-1881 is an authenticated access-control flaw in the Broadstreet plugin for WordPress. A missing validation check on a user-controlled key in the get_sponsored_meta AJAX action can let Subscriber-level and higher users read private post metadata they should not be able to access. The issue is rated medium severity (CVSS 4.3) and is primarily a confidentiality concern.

MEDIUM broadstreetads CVE published 2026-05-13

CVE-2025-9989

The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. [truncated]

MEDIUM broadstreetads CVE published 2026-05-13

CVE-2025-9988

The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers. The vulnerability allows attackers to potentially create unauthorized advertisers, which could lead to [truncated]

MEDIUM broadstreetads CVE published 2026-05-13

CVE-2025-9987

The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected and private business details. Defenders should assess exposure and prioritize verification of plugin ver [truncated]