The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Broadstreetads
Broadstreetads broadstreet |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:broadstreetads:broadstreet:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Broadstreetads
Broadstreetads broadstreet |
Tue, 10 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Jun 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 09 Jun 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
Title | Broadstreet < 1.51.8 - Reflected XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-06-09T06:00:14.489Z
Updated: 2025-06-10T20:05:25.390Z
Reserved: 2025-05-13T12:58:18.602Z
Link: CVE-2025-4652

Updated: 2025-06-10T20:05:20.879Z

Status : Analyzed
Published: 2025-06-09T06:15:25.740
Modified: 2025-06-12T16:15:48.467
Link: CVE-2025-4652

No data.