Junglewise Threat Intelligence

CVE-2026-1881: Broadstreet WordPress plugin IDOR in get_sponsored_meta

CVE-2026-1881 · Severity: medium · CVSS 4.3 · Published 2026-05-21

Technologies: Broadstreet. Vendors: Broadstreet.

Executive brief

The Broadstreet plugin for WordPress, which is used for managing digital advertisements and sponsored content, contains a security flaw that allows logged-in users to view sensitive internal information. By exploiting this vulnerability, an attacker with a basic account (such as a subscriber) can access private metadata associated with posts that should not be visible to them. This could lead to the exposure of internal configuration details or private content details, potentially aiding further attacks or compromising site confidentiality.

Technical details

The Broadstreet plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability via the 'get_sponsored_meta' AJAX action. The root cause is a lack of proper validation and authorization checks on a user-controlled key used to retrieve post metadata. An authenticated attacker with Subscriber-level permissions or higher can send crafted AJAX requests to disclose metadata from private posts. This vulnerability is tracked as CWE-639. A patch is available in version 1.53.2, which implements the necessary validation to prevent unauthorized metadata disclosure.

Affected products

  • Broadstreet Broadstreet Up to, and including, 1.52.2

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory

References