Broadly for WordPress
Broadly for WordPress has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Broadly for WordPress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. Broadly for WordPress is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.3.23.
CVE-2025-30938Broadly for WordPress <= 3.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Broadly for WordPress
Author
broadly
Broadly allows your business to easily communicate with your customers. Manage your online reputation and customer communications across SMS and email from any device, in real-time. Features include: Web Chat. Broadly’s Web Chat encourages prospective customers to get in touch with you immediately. Engage with them in real time, and convert more visitors into qualified leads and customers. All Your Reviews. Show off your business’s great reviews with the Broadly for WordPress plugin. We aggregate reviews from Google, Facebook, TripAdvisor, NextDoor and more, and display them on your website. Native Embeds. The Broadly for WordPress plugin allows Broadly embeds to become native on your website – operating without JavaScript – and helping with SEO and new, fresh content. WordPress Support. WordPress is a powerful and flexible platform for managing websites, and the Broadly for WordPress plugin provides simple and easy native support.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C