WordPress security by component
Broadstreet Ads
Plugin description
Broadstreet Ads manages and displays advertising campaigns, placements, creatives, and sponsorship content on WordPress websites.
Broadstreet Ads (broadstreet) is a WordPress plugin with 11 published CVE records in this archive. The latest tracked vulnerability was published May 21, 2026; the highest published CVSS base score is 7.6.
Plugin slug:
broadstreetLatest vulnerability
CVE-2026-1881: Broadstreet: Broken access control
Broadstreet is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 1.52.2.
| Safe version |
|
||
|---|---|---|---|
| May 21, 2026 |
CVE-2026-1881
Broadstreet: Broken access control
Broadstreet is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 1.52.2.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 13, 2026 |
CVE-2025-9989
Broadstreet: Cross-site scripting
Broadstreet is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.53.1.
|
See mitigation notes |
CVE4.4
NVDPending
|
| May 13, 2026 |
CVE-2025-9988
Broadstreet: A security weakness
Broadstreet is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.53.1.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 13, 2026 |
CVE-2025-9987
Broadstreet: Sensitive information exposure
Broadstreet is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 1.53.1.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 12, 2026 |
CVE-2026-45210
Broadstreet Ads: A security weakness
Broadstreet Ads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.52.2.
|
1.53.2 |
CVE5.4
NVDPending
|
| Jan 22, 2026 |
CVE-2025-69311
Broadstreet Ads: A security weakness
Broadstreet Ads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Jun 09, 2025 |
CVE-2025-4652
Broadstreet: Cross-site scripting
Broadstreet is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| May 16, 2025 |
CVE-2025-48113
Broadstreet Ads: Cross-site scripting
Broadstreet Ads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 08, 2025 |
CVE-2025-32211
Broadstreet Ads: Cross-site scripting
Broadstreet Ads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32270
Broadstreet Ads: Cross-site request forgery
Broadstreet Ads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 25, 2025 |
CVE-2024-11825
Broadstreet: Cross-site scripting
Broadstreet is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|