CVE-2025-9988Medium· 4.3▾ SunlitThe Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attac…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-9294Medium· 4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and includ…
CVE-2025-22168Medium· 4.3Jira Align is vulnerable to an authorization issue
CVE-2025-11321Medium· 4.3A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4
CVE-2025-11080Medium· 4.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4
CVE-2025-10819Medium· 4.3A security vulnerability has been detected in fuyang_lipengjun platform 1.0
CVE-2025-10277Medium· 6.3A vulnerability was detected in YunaiV yudao-cloud up to 2025.09