Impact
The vulnerability is an unauthenticated broken access control in the WordPress Business Directory plugin, affecting all releases up to version 6.4.23. A user who is not logged in can invoke plugin functionality that should be restricted to authenticated administrators, potentially allowing modification or deletion of listings and other sensitive data. This flaw arises from missing authorization checks (CWE‑862) and enables an attacker to tamper with the site’s content without authentication.
Affected Systems
The affected product is the WordPress Business Directory plugin, developed by Strategy11 Team, with vulnerable releases up to and including version 6.4.23. Any WordPress installation that has this plugin installed and not updated to a later version is at risk.
Risk and Exploitability
The CVSS score of 6.6 indicates medium severity, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from the current data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a simple web request to the plugin’s endpoints, requiring no authentication. Exploitation could lead to unauthorized modification or deletion of directory listings, resulting in integrity loss and possible site defacement.
OpenCVE Enrichment