Stored Cross-Site Scripting Vulnerability in Broadstreet Plugin for WordPress
CVE-2025-9989
4.4MEDIUM
What is CVE-2025-9989?
The Broadstreet plugin for WordPress has a vulnerability that allows authenticated attackers with administrator permissions to execute arbitrary web scripts through Stored Cross-Site Scripting. This issue arises from inadequate input sanitization and output escaping in admin settings, posing a risk primarily in multi-site installations where the unfiltered_html setting is disabled. When a user accesses a page with the injected script, it can lead to unauthorized actions, making it essential for site administrators to update to a secure version.
Affected Version(s)
Broadstreet 0 <= 1.53.1