Executive brief
The Broadstreet plugin for WordPress, which is used for managing digital advertisements and sponsored content, contains a security flaw that allows unauthorized data access. An attacker with a basic user account can bypass normal restrictions to view sensitive business information and content that was intended to be private or password-protected. This could lead to the exposure of confidential business details or proprietary sponsored data.
Technical details
The Broadstreet plugin for WordPress is vulnerable to sensitive information exposure due to an insecure implementation of the get_sponsored_meta() AJAX action. The vulnerability exists in all versions up to and including 1.53.1. The root cause is a lack of proper authorization checks or capability validation within the AJAX handler, allowing any authenticated user—including those with low-level 'subscriber' permissions—to trigger the function. By sending a crafted request to the WordPress AJAX endpoint, an attacker can retrieve metadata associated with sponsored content, including information from posts or business details that are marked as private or password-protected. A patch has been identified in recent changesets to address this unauthorized data access.
Affected products
- Broadstreet Broadstreet Up to, and including, 1.53.1
Timeline
- 2026-05-13: disclosed: Initial publication of the vulnerability advisory.
- 2026-05-13: advisory: NVD and Wordfence published details regarding CVE-2025-9987.