Impact
The vulnerability is a cross‑site scripting flaw that allows an attacker to insert unsanitized HTML or JavaScript into the Business Directory plugin’s output on WordPress sites. Because the input is not properly validated, arbitrary scripts can be executed in the browsers of users who visit the affected pages. This flaw is classified as CWE‑79.
Affected Systems
The affected product is the Business Directory plugin from the Strategy11 Team for WordPress. All releases up to and including version 6.4.22 are impacted; the fix is available in version 6.4.23 and later. No other vendors or product families are listed, so only installations of this plugin on WordPress sites need to be assessed.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate impact. No EPSS score is available, so the exploitation probability remains unquantified. It is inferred that the flaw can be triggered via a crafted request to the plugin’s interface, since authentication is not required. It can be inferred that any visitor to a page containing an injected script would be affected, but this scenario is not explicitly stated in the data. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment