Description
The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Published: 2026-05-13
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Broadstreet plugin contains a stored cross‑site scripting flaw in its administrative settings that is not properly sanitized or escaped. An attacker who has administrator‑level access can store malicious scripts in the plugin’s settings, which are then rendered unmodified on pages accessed by anyone in the site. The injected code runs in the victim’s browser, enabling actions such as session hijacking, credential theft, content defacement, or execution of further malicious payloads. This vulnerability directly jeopardizes the confidentiality, integrity, and availability of the web application’s front‑end for all users who view pages that include the chart settings.

Affected Systems

All installations of the Broadstreet plugin for WordPress with versions up to and including 1.53.1 on multi‑site WordPress sites where the unfiltered_html capability is disabled are affected. The vulnerability resides in the plugin’s administrative configuration screens and propagates any user‑submitted content into page output without proper escaping.

Risk and Exploitability

The CVSS score of 4.4 indicates a low overall severity; however, the flaw requires an attacker to have administrator credentials, which is a significant entity‑level compromise. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed or recorded. The likely attack vector involves a legitimate admin logging into the WordPress dashboard, navigating to the Broadstreet settings, and injecting malicious code that will later execute in browsers of all site users. Because the attack requires administrative access, remediation through account management and plugin updates is the recommended approach.

Generated by OpenCVE AI on May 13, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Broadstreet to version 1.53.2 or later, which removes the unsanitized input handling in the admin settings.
  • If an upgrade is not immediately possible, remove or disable the Broadstreet plugin entirely to prevent the stored XSS from being served.
  • Restrict the number of administrator accounts and enforce the principle of least privilege so that only trusted users have the ability to modify plugin settings.

Generated by OpenCVE AI on May 13, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Broadstreetads
Broadstreetads broadstreet
Wordpress
Wordpress wordpress
Vendors & Products Broadstreetads
Broadstreetads broadstreet
Wordpress
Wordpress wordpress

Wed, 13 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Title Broadstreet <= 1.53.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Broadstreetads Broadstreet
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-13T10:21:26.150Z

Reserved: 2025-09-04T13:50:38.832Z

Link: CVE-2025-9989

cve-icon Vulnrichment

Updated: 2026-05-13T10:18:37.271Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T05:16:13.740

Modified: 2026-05-13T14:43:46.717

Link: CVE-2025-9989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T06:30:25Z

Weaknesses