Description
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
Published: 2026-06-29
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control in the WordPress Business Directory plugin, affecting all releases up to version 6.4.23. A user who is not logged in can invoke plugin functionality that should be restricted to authenticated administrators, potentially allowing modification or deletion of listings and other sensitive data. This flaw arises from missing authorization checks (CWE‑862) and enables an attacker to tamper with the site’s content without authentication.

Affected Systems

The affected product is the WordPress Business Directory plugin, developed by Strategy11 Team, with vulnerable releases up to and including version 6.4.23. Any WordPress installation that has this plugin installed and not updated to a later version is at risk.

Risk and Exploitability

The CVSS score of 6.6 indicates medium severity, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from the current data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a simple web request to the plugin’s endpoints, requiring no authentication. Exploitation could lead to unauthorized modification or deletion of directory listings, resulting in integrity loss and possible site defacement.

Generated by OpenCVE AI on June 29, 2026 at 16:36 UTC.

Remediation

Vendor Solution

Update the WordPress Business Directory Plugin to the latest available version (at least 6.4.24).


OpenCVE Recommended Actions

  • Update the WordPress Business Directory plugin to version 6.4.24 or later, as recommended by the vendor.
  • Remove any residual or backup copies of earlier plugin versions from the server to eliminate re‑installation vectors.
  • Ensure that role‑based access controls are enforced for all plugin functions, verifying that only users with appropriate administrative privileges can perform sensitive actions.

Generated by OpenCVE AI on June 29, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Strategy11team
Strategy11team business Directory Plugin
Wordpress
Wordpress wordpress
Vendors & Products Strategy11team
Strategy11team business Directory Plugin
Wordpress
Wordpress wordpress

Mon, 29 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
Title WordPress Business Directory plugin <= 6.4.23 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Strategy11team Business Directory Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-29T15:51:01.110Z

Reserved: 2026-06-24T12:45:19.179Z

Link: CVE-2026-57339

cve-icon Vulnrichment

Updated: 2026-06-29T15:50:57.279Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T09:45:03Z

Weaknesses