Junglewise Threat Intelligence

CVE-2026-57328: Strategy11 Team Business Directory XSS in WordPress plugin

CVE-2026-57328 · Severity: medium · CVSS 6.5 · Published 2026-06-29

Technologies: Strategy11 Business Directory Plugin. Vendors: Strategy11.

Executive brief

The Business Directory plugin for WordPress, which allows site owners to create online directories and listings, contains a security flaw that could allow users with basic 'Subscriber' accounts to inject malicious scripts. If a site administrator or another user views a page containing this injected content, the script could execute in their browser, potentially leading to unauthorized actions or data theft. This vulnerability could be used to redirect visitors to malicious websites or display unauthorized advertisements.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Strategy11 Team Business Directory plugin for WordPress (versions <= 6.4.22) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Subscriber' level privileges to inject malicious JavaScript into the application. Successful exploitation requires a victim (such as an administrator) to interact with the affected page or perform a specific action, leading to the execution of the script in the context of the victim's session. The issue is resolved in version 6.4.23.

Affected products

  • Strategy11 Team Business Directory <= 6.4.22

Timeline

  • 2026-04-03: disclosed: Reported by she11f
  • 2026-06-29: advisory: Published by Patchstack and NVD
  • 2026-06-29: patched: Fixed in version 6.4.23

References

Related threats