Junglewise Threat Intelligence

CVE-2025-9989: Broadstreet WordPress plugin Stored XSS in admin settings

CVE-2025-9989 · Severity: medium · CVSS 4.4 · Published 2026-05-13

Technologies: Broadstreet. Vendors: Broadstreet.

Executive brief

The Broadstreet plugin for WordPress, which is used for managing digital advertisements, contains a security vulnerability that allows high-level users to inject malicious scripts into the website's administrative settings. If exploited, these scripts could execute in the browsers of other users who visit the affected pages, potentially leading to unauthorized actions or data theft. This issue primarily impacts WordPress multi-site environments or specific configurations where standard security restrictions on HTML content have been disabled.

Technical details

The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its administrative settings. An authenticated attacker with administrator-level privileges can inject arbitrary web scripts into the database. These scripts are then executed in the context of any user accessing the affected administrative pages. The vulnerability is specifically exploitable in WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. A patch appears to have been addressed in changeset 3524817.

Affected products

  • Broadstreet Broadstreet Up to, and including, 1.53.1

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats