Sensitive Information Exposure in Broadstreet Plugin for WordPress
CVE-2025-9987

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 May 2026

What is CVE-2025-9987?

The Broadstreet plugin for WordPress is susceptible to a Sensitive Information Exposure vulnerability through its get_sponsored_meta() AJAX action. This flaw allows authenticated attackers, who have subscriber-level access or higher, to extract sensitive data from password-protected and private business details, potentially compromising confidential information and user privacy.

Affected Version(s)

Broadstreet 0 <= 1.53.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

greenhats
.