Description
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw that allows an attacker to insert unsanitized HTML or JavaScript into the Business Directory plugin’s output on WordPress sites. Because the input is not properly validated, arbitrary scripts can be executed in the browsers of users who visit the affected pages. This flaw is classified as CWE‑79.

Affected Systems

The affected product is the Business Directory plugin from the Strategy11 Team for WordPress. All releases up to and including version 6.4.22 are impacted; the fix is available in version 6.4.23 and later. No other vendors or product families are listed, so only installations of this plugin on WordPress sites need to be assessed.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate impact. No EPSS score is available, so the exploitation probability remains unquantified. It is inferred that the flaw can be triggered via a crafted request to the plugin’s interface, since authentication is not required. It can be inferred that any visitor to a page containing an injected script would be affected, but this scenario is not explicitly stated in the data. The vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on June 29, 2026 at 17:25 UTC.

Remediation

Vendor Solution

Update the WordPress Business Directory Plugin to the latest available version (at least 6.4.23).


OpenCVE Recommended Actions

  • Update the WordPress Business Directory plugin to version 6.4.23 or newer.
  • Apply proper input validation and output escaping on all data fields handled by the plugin.
  • Review existing content for injected scripts and remove any malicious code found.

Generated by OpenCVE AI on June 29, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Strategy11team
Strategy11team business Directory Plugin
Wordpress
Wordpress wordpress
Vendors & Products Strategy11team
Strategy11team business Directory Plugin
Wordpress
Wordpress wordpress

Mon, 29 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
Title WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Strategy11team Business Directory Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-29T15:06:51.848Z

Reserved: 2026-06-24T12:45:08.530Z

Link: CVE-2026-57326

cve-icon Vulnrichment

Updated: 2026-06-29T15:06:47.570Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:04:33Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')