Unauthorized Access Vulnerability in Broadstreet Plugin for WordPress
CVE-2025-9988
4.3MEDIUM
What is CVE-2025-9988?
The Broadstreet plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to create advertisers without proper authorization checks. This security flaw stems from a missing capability verification on the create_advertiser AJAX action, making it a significant risk for unintended privilege escalation and management of advertiser accounts.
Affected Version(s)
Broadstreet 0 <= 1.53.1