CVE-2025-32270
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-32270 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Broadstreet's Broadstreet platform. This issue permits malicious actors to submit unintended commands or actions on behalf of a victim who is currently authenticated on the targeted website. The vulnerability exists in Broadstreet versions from n/a through 1.51.1, putting numerous users at potential risk. An attacker could exploit this flaw to manipulate user actions, such as changing settings, making unauthorized purchases, or gaining access to sensitive information. It is crucial for users to update their Broadstreet platform to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress