CVE-2025-9988
EUVD-2025-20981913.05.2026, 05:16
The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| broadstreetads | broadstreet | 𝑥 ≤ 1.53.1 | CNA |
Common Weakness Enumeration