Impact
The Business Directory plugin for WordPress is affected by an unauthenticated Insecure Direct Object Reference flaw. An attacker can manipulate direct URLs or identifiers to access, modify, or delete data objects that should be protected. The primary consequence is that sensitive business listings or related data could be exposed, altered, or removed by unauthorized users.
Affected Systems
Vendors: Strategy11 Team. Product: Business Directory plugin for WordPress, versions up to and including 6.4.26. Any installation of these versions is vulnerable.
Risk and Exploitability
The flaw is rated with a CVSS score of 6.5, indicating a moderate severity. The EPSS score is not available, so the current exploitation probability cannot be assessed. The vulnerability is not listed in CISA KEV. Likely attack vectors are unauthenticated users who guess or brute‑force object identifiers through the public web interface. Exploitation requires no special privileges beyond internet connectivity to the target site.
OpenCVE Enrichment