Description
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
Published: 2025-08-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Simple Business Directory Pro plugin is an incorrect privilege assignment flaw that permits an attacker to elevate privileges beyond the level intended for their user role. This flaw can allow a user with ordinary access to gain higher-level capabilities, such as editing or deleting critical content or potentially accessing administrative functions. The weakness is classified as CWE‑266, addressing improper authorization.

Affected Systems

All installations of the QuantumCloud Simple Business Directory Pro WordPress plugin running version 15.6.9 or earlier are affected. Users who have deployed the plugin before the 15.6.9 release remain vulnerable unless the plugin has been upgraded to a fixed version.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical risk, yet the EPSS score of less than 1% suggests that actual exploitation attempts are currently very rare. The vulnerability is not listed in the CISA KEV catalog. While the CVE description does not explicitly state the authentication requirements, it is inferred that an attacker would likely need some level of authenticated access to the WordPress site to exploit the privilege escalation, and the attack would be carried out through normal plugin functionality such as attempting to edit or manage directory entries. The likely attack vector is the plugin’s privileged functions, which, if accessed by a lower‑privileged user, could grant them higher capabilities.

Generated by OpenCVE AI on April 30, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor update of the Simple Business Directory Pro plugin (version 15.6.9 or higher).
  • If an immediate update cannot be applied, deactivate or remove the plugin from the WordPress installation to eliminate the vulnerability surface.
  • Restrict WordPress user role permissions to the minimum required level to limit any residual privilege escalation potential.

Generated by OpenCVE AI on April 30, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25322 Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through n/a.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through n/a. Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 20 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through n/a.
Title WordPress Simple Business Directory Pro Plugin < 15.6.9 - Privilege Escalation Vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:26.711Z

Reserved: 2025-07-03T14:51:13.582Z

Link: CVE-2025-53580

cve-icon Vulnrichment

Updated: 2025-08-20T14:29:16.189Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:43.590

Modified: 2026-04-23T15:32:38.560

Link: CVE-2025-53580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T16:15:06Z

Weaknesses