Broadstreet WordPress plugin < 1.51.8 contains a reflected XSS caused by unsanitised and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin, exploit requires victim interaction.
id: CVE-2025-4652
info:
name: Broadstreet WordPress plugin - Reflected XSS
author: Sourabh-Sahu
...