CVE-2025-9988
Basic Information
| Severity | MEDIUM |
|---|---|
| Base Score | 4.3 |
| CNA | Wordfence |
| Published Date | 2026-05-13 00:26:38 UTC |
| Last Modified | 2026-05-13 06:23:08 UTC |
| CVE.org Link | https://www.cve.org/CVERecord?id=CVE-2025-9988 |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2025-9988 |
Description
The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers.
Affected Products
| Vendor | Product |
|---|---|
| broadstreetads | broadstreet |