Impact
Unauthenticated Cross Site Scripting (XSS) exists in the WordPress Business Directory plugin versions 6.4.25 and earlier, allowing an attacker to inject arbitrary script code into the web pages presented to visitors. The flaw arises from insufficient input validation, classified under CWE‑79, and can lead to client‑side script execution without requiring user authentication.
Affected Systems
The vulnerability affects the Strategy11 Team Business Directory plugin for WordPress. All installations running version 6.4.25 or older are impacted, as the issue was remediated in the subsequent 6.4.26 release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. Attackers do not need prior authentication; any visitor to the affected site can trigger the fault, potentially compromising the session integrity of other users and allowing widespread script execution across the website.
OpenCVE Enrichment