Impact
The Business Directory plugin for WordPress contains an injection flaw that allows a subscriber to embed malicious script code that is later rendered in an unescaped context. The flaw can lead to execution of arbitrary JavaScript in the browser of any visitor viewing the affected content, allowing cookie theft, session hijack, or malicious redirects. This represents a moderate severity weakness for confidentiality and integrity of the user session.
Affected Systems
WordPress sites that have the Business Directory plugin by Strategy11 Team installed in a version 6.4.24 or earlier. The vulnerability is present only in the specified plugin and affects sites where the plugin renders subscriber‑supplied content without proper sanitization.
Risk and Exploitability
The CVSS score of 6.5 categorizes the flaw as moderate. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower likelihood of public exploitation at this time. The attack vector is inferred to be through user‑submitted content that the plugin stores and later displays, requiring the attacker to craft a malicious script and submit it via the plugin’s interface.
OpenCVE Enrichment