Broadstreet

Broadstreet has 11 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 11 are fixed as of September 2026. Their average CVSS score is 5.1, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (45%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key.

Every one of the 11 issues recorded for Broadstreet has a vendor fix available, so running the current release closes all known holes.

9 independent researchers contributed these findings, most of them (3) reported by greenhats. Broadstreet is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.1/ 10
Patch Coverage100%
Open

0

Fixed

11

Get automatic notifications for all Broadstreet vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-48113

Broadstreet <= 1.51.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

11 records
2026-05-20 13:15CVE-2026-1881
4.3
Medium
Tarcísio Luchesi De Almeida Silva (Poystick)Yes
2026-05-12 15:43CVE-2025-9988
4.3
Medium
greenhatsYes
2026-05-12 15:29CVE-2025-9987
5.3
Medium
greenhatsYes
2026-05-12 15:28CVE-2025-9989
4.4
Medium
greenhatsYes
2026-02-21 00:00CVE-2026-45210
4.3
Medium
Nabil IrawanYes
2026-01-19 00:00CVE-2025-69311
4.3
Medium
Que Thanh TuanYes
2025-05-29 00:00CVE-2025-4652
6.1
Medium
Tommaso GregoriYes
2025-05-16 00:00CVE-2025-48113
6.4
Medium
kmaron1nYes
2025-04-07 00:00CVE-2025-32211
6.4
Medium
Kévin Mosbahi (Mika)Yes
2025-04-04 00:00CVE-2025-32270
4.3
Medium
Nguyen Xuan ChienYes
Showing 1–10 of 11 reports
Broadstreet banner
Latestv1.53.3
5.0(2)
100/100
Last Updated
2026-08-04 (1mo ago)
Active Installs
800+
Downloads
51,561
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2012-10-17 (14y ago)

For Broadstreet Ad Manager users. Integrate Broadstreet’s Ad Manager for Hyperlocal News, Magazine, and Niche Publishers into your Broadstreet site. Install Broadstreet configuration with best practices automatically Drop zones into widget areas or via shortcode Place zones in-story ad-hoc or after certain paragraphs Automatically send category names as keywords to the adserver Restrict ads from appearing on certain pages or categories How to: Install the plugin Go to Settings->Broadstreet Enter your Access Token and confirm that it’s valid (we’ll check automatically) Go to Appearance->Widgets, and use the new &#8216;Broadstreet Ad Zone’ widget To learn more about Broadstreet, and how it can help you as a local publisher, send an email to frontdesk@broadstreetads.com. How can I report security bugs? You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability. Fix Log 1.2.3: Fixed image upload bug affecting minority of WP installations 1.8.1: Fixed asset base URL making the settings page ugly 1.8.1: Fixed excerpt filter (special thanks Justin)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C