Executive brief
Broadstreet Ads, a WordPress plugin used for managing digital advertisements, contains a security flaw that fails to properly check user permissions. This allows logged-in users with low-level access, such as subscribers, to perform actions or modify settings that should be restricted to administrators. While the risk is considered moderate, it could lead to unauthorized changes to the site's advertising configuration.
Technical details
The Broadstreet Ads plugin for WordPress (versions up to and including 1.52.2) suffers from a Broken Access Control vulnerability (CWE-862). The issue stems from a failure to implement proper authorization checks or nonce validation on certain functions. An attacker authenticated with basic 'Subscriber' privileges can exploit this over the network to perform actions that should require higher administrative permissions. This can result in unauthorized modifications to plugin settings or data. The vulnerability is addressed in version 1.53.2.
Affected products
- Broadstreet Broadstreet Ads <= 1.52.2
Timeline
- 2026-01-22: other: Vulnerability reported by researcher
- 2026-02-21: disclosed: Initial disclosure by Patchstack
- 2026-02-21: patched: Patch released in version 1.53.2
- 2026-05-12: advisory: CVE published to NVD