Executive brief
The Business Directory Plugin for WordPress, which allows users to create directory listings on their websites, is vulnerable to a security flaw that could allow attackers to run malicious scripts. By tricking a site visitor or administrator into clicking a specific link, an attacker could steal session information, redirect users to malicious websites, or deface the site. This issue affects all versions up to and including 6.4.22.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Business Directory Plugin for WordPress (versions <= 6.4.22) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a specially crafted link to a user. If the user clicks the link, the attacker's script executes within the context of the victim's browser session. This can lead to unauthorized access to session tokens or the performance of actions on behalf of the user. The vulnerability is resolved in version 6.4.23.
Affected products
- Strategy11 Team Business Directory Plugin <= 6.4.22
Timeline
- 2026-03-19: other: Vulnerability reported by 0xManticore
- 2026-06-29: disclosed: CVE published and advisory released by Patchstack
- 2026-06-29: patched: Version 6.4.23 released to address the vulnerability