Impact
The Broadstreet WordPress plugin contains a missing capability check for the create_advertiser AJAX action. This flaw allows any authenticated user holding at least the Subscriber role to invoke the endpoint and create advertiser entries. While the vulnerability does not grant arbitrary code execution, data exfiltration, or privilege escalation, it permits the creation of advertising entities without proper authorization.
Affected Systems
All WordPress sites that have the Broadstreet plugin installed and are running version 1.53.1 or earlier are affected. The issue targets the AJAX endpoint that supplies advertiser creation functionality to authenticated users.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not tracked in CISA KEV. Exploitation requires a legitimate WordPress login with at least Subscriber privileges, followed by an AJAX request to the vulnerable endpoint. The attack vector is internal to the site’s authenticated interface and does not rely on network-level exposure.
OpenCVE Enrichment