Junglewise Threat Intelligence

CVE-2026-45210: Broadstreet Broadstreet Ads missing authorization

CVE-2026-45210 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Vendors: Broadstreet.

Executive brief

Broadstreet Ads, a WordPress plugin used for managing digital advertisements, contains a security flaw that fails to properly check user permissions. This allows logged-in users with low-level access, such as subscribers, to perform actions or modify settings that should be restricted to administrators. While the risk is considered moderate, it could lead to unauthorized changes to the site's advertising configuration.

Technical details

The Broadstreet Ads plugin for WordPress (versions up to and including 1.52.2) suffers from a Broken Access Control vulnerability (CWE-862). The issue stems from a failure to implement proper authorization checks or nonce validation on certain functions. An attacker authenticated with basic 'Subscriber' privileges can exploit this over the network to perform actions that should require higher administrative permissions. This can result in unauthorized modifications to plugin settings or data. The vulnerability is addressed in version 1.53.2.

Affected products

  • Broadstreet Broadstreet Ads <= 1.52.2

Timeline

  • 2026-01-22: other: Vulnerability reported by researcher
  • 2026-02-21: disclosed: Initial disclosure by Patchstack
  • 2026-02-21: patched: Patch released in version 1.53.2
  • 2026-05-12: advisory: CVE published to NVD

References