Impact
The Broadstreet WordPress plugin contains a Sensitive Information Exposure flaw in the get_sponsored_meta AJAX action. Authenticated users with subscriber-level permissions or higher can retrieve password protected and private business details, exposing confidential data that would otherwise be restricted.
Affected Systems
All installations of the Broadstreet plugin for WordPress up to and including version 1.53.1 are affected. The vulnerability is present regardless of site configuration or additional plugins.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not actively exploited in the wild. The attack requires valid subscriber credentials and direct access to the plugin’s AJAX endpoint, so exploitation is limited to authorized site users.
OpenCVE Enrichment