Impact
The vulnerability is a stored XSS flaw that occurs when user input in the Broadstreet Ads plugin is not properly neutralised before being rendered. An attacker could inject malicious JavaScript that would run in the context of any user who views the affected content, potentially allowing credential theft, session hijacking, or defacement.
Affected Systems
Broadstreet Ads plugin for WordPress, affecting all installations using version 1.51.2 or earlier. The issue applies to the plugin’s ad‑creation and management interfaces where data is persisted and later displayed.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity risk. The EPSS score indicates a very low current exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalogue. Nevertheless, the stored nature of the flaw means that any injected payload will persist until manually removed, and the lack of a robust input‑validation mechanism increases the likelihood that an attacker could successfully deliver harmful code. The likely attack vector is through a legitimate user account that can add or edit ads, allowing an attacker to embed script via ad content that then executes on subsequent page loads.
OpenCVE Enrichment
EUVD