Broadstreet
Broadstreet has 11 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 11 are fixed as of September 2026. Their average CVSS score is 5.1, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 6 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (45%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key.
Every one of the 11 issues recorded for Broadstreet has a vendor fix available, so running the current release closes all known holes.
9 independent researchers contributed these findings, most of them (3) reported by greenhats. Broadstreet is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-48113Broadstreet <= 1.51.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Broadstreet
Author
Broadstreet
For Broadstreet Ad Manager users. Integrate Broadstreet’s Ad Manager for Hyperlocal News, Magazine, and Niche Publishers into your Broadstreet site. Install Broadstreet configuration with best practices automatically Drop zones into widget areas or via shortcode Place zones in-story ad-hoc or after certain paragraphs Automatically send category names as keywords to the adserver Restrict ads from appearing on certain pages or categories How to: Install the plugin Go to Settings->Broadstreet Enter your Access Token and confirm that it’s valid (we’ll check automatically) Go to Appearance->Widgets, and use the new ‘Broadstreet Ad Zone’ widget To learn more about Broadstreet, and how it can help you as a local publisher, send an email to frontdesk@broadstreetads.com. How can I report security bugs? You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability. Fix Log 1.2.3: Fixed image upload bug affecting minority of WP installations 1.8.1: Fixed asset base URL making the settings page ugly 1.8.1: Fixed excerpt filter (special thanks Justin)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C