CVE-2025-9987
EUVD-2025-20981813.05.2026, 05:16
The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected and private business details.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| broadstreetads | broadstreet | 𝑥 ≤ 1.53.1 | CNA |
Common Weakness Enumeration