Impact
A missing authorization check in the Strategy11 Team Business Directory WordPress plugin allows an attacker to bypass intended access controls. This vulnerability can lead to unauthorized manipulation of directory data, potentially exposing or altering sensitive information stored through the plugin.
Affected Systems
The vulnerability applies to the Business Directory plugin developed by Strategy11 Team. Any installation running a version up to and including 6.4.18 is affected. Versions released after 6.4.18 are not listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity level on the CVSS scale, and the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog. An attacker would need web application access, such as a legitimate user session or the ability to craft requests against the plugin’s endpoints, to exploit the broken access control. The attack can be performed within the web application context without system‑level privileges.
OpenCVE Enrichment