CVE-2025-4652
Broadstreet < 1.51.8 - Reflected XSS
Record summary
CVE-2025-4652 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BroadstreetDefault status: unaffected | CVE List | Before 1.51.8 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMBroadstreet WordPress plugin - Reflected XSSCVSS 6.1
Broadstreet WordPress plugin < 1.51.8 contains a reflected XSS caused by unsanitised and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin, exploit requires victim interaction.
Impact
Attackers can execute scripts in admin users' browsers, potentially leading to session hijacking or privilege abuse.
Remediation
Update to version 1.51.8 or later.
Source: ProjectDiscovery