Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Business Directory plugin versions up to 6.4.26. It allows a user without proper authentication to perform actions normally restricted to administrators or privileged users, such as creating, editing, or deleting business listings. This can lead to data tampering, unauthorized disclosure of sensitive information, and potential reputation damage for site owners.
Affected Systems
WordPress sites using the Business Directory plugin version 6.4.26 or earlier, produced by Strategy11. The vulnerability is tied specifically to the plugins found in the version series 6.4.x, particularly 6.4.26.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the lack of EPSS data means the likelihood of exploitation cannot be quantified, but the flaw remains dangerous because it requires no authentication. The vulnerability is not listed in the CISA KEV catalog, but its impact is sufficient to warrant immediate remediation. Exploitation can occur simply by accessing proxied endpoints that lack proper authorization checks, allowing unauthenticated users to manipulate business listing content.
OpenCVE Enrichment