Stored Cross-Site Scripting Vulnerability in Broadstreet Plugin for WordPress
CVE-2025-9989

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 May 2026

What is CVE-2025-9989?

The Broadstreet plugin for WordPress has a vulnerability that allows authenticated attackers with administrator permissions to execute arbitrary web scripts through Stored Cross-Site Scripting. This issue arises from inadequate input sanitization and output escaping in admin settings, posing a risk primarily in multi-site installations where the unfiltered_html setting is disabled. When a user accesses a page with the injected script, it can lead to unauthorized actions, making it essential for site administrators to update to a secure version.

Affected Version(s)

Broadstreet 0 <= 1.53.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

greenhats
.