Sensitive Information Exposure in Broadstreet Plugin for WordPress
CVE-2025-9987
5.3MEDIUM
What is CVE-2025-9987?
The Broadstreet plugin for WordPress is susceptible to a Sensitive Information Exposure vulnerability through its get_sponsored_meta() AJAX action. This flaw allows authenticated attackers, who have subscriber-level access or higher, to extract sensitive data from password-protected and private business details, potentially compromising confidential information and user privacy.
Affected Version(s)
Broadstreet 0 <= 1.53.1