PT-2026-40558 · Broadstreetads · Broadstreet

Greenhats

·

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2025-9987

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get sponsored meta() AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected and private business details.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-9987

Affected Products

Broadstreet