Broadstreet WordPress Plugin Insecure Direct Object Reference Vulnerability Allowing Private Post Metadata Disclosure

Vulnerability

A vulnerability exists in the Broadstreet plugin for WordPress, in all versions up to and including 1.52.2. The issue is an Insecure Direct Object Reference (IDOR) vulnerability, which arises from inadequate validation of user-controlled keys in the get_sponsored_meta AJAX action. This flaw enables authenticated attackers with Subscriber-level access and above to access and disclose private post metadata.

Impact

Exploitation of this vulnerability allows for unauthorized disclosure of private post metadata.

Remediation

Users are advised to update the Broadstreet WordPress plugin to version 1.53.2 or a newer patched version.

Added: May 21, 2026, 2:19 AM
Updated: May 21, 2026, 2:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
0.0
relevance
9.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.