
CVE-2026-1881 The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.52.2 via the get_sponsored_meta AJAX acti… https://www.cve.org/CVERecord?id=CVE-2026-1881
Post summary
The entry announces an IDOR vulnerability in the Broadstreet WordPress plugin up to version 1.52.2, targeted through an AJAX action, but provides no exploit or mitigation details.

