Broadstreet
- <= 1.52.2
A vulnerability exists in the Broadstreet plugin for WordPress, in all versions up to and including 1.52.2. The issue is an Insecure Direct Object Reference (IDOR) vulnerability, which arises from inadequate validation of user-controlled keys in the get_sponsored_meta AJAX action. This flaw enables authenticated attackers with Subscriber-level access and above to access and disclose private post metadata.
Exploitation of this vulnerability allows for unauthorized disclosure of private post metadata.
Users are advised to update the Broadstreet WordPress plugin to version 1.53.2 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.