CVE-2025-9987
Basic Information
| Severity | MEDIUM |
|---|---|
| Base Score | 5.3 |
| CNA | Wordfence |
| Published Date | 2026-05-13 00:26:40 UTC |
| Last Modified | 2026-05-13 06:22:09 UTC |
| CVE.org Link | https://www.cve.org/CVERecord?id=CVE-2025-9987 |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2025-9987 |
Description
The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected and private business details.
Affected Products
| Vendor | Product |
|---|---|
| broadstreetads | broadstreet |