Executive brief
The Business Directory plugin for WordPress, which allows site owners to create local or professional directories, contains a security flaw in its access control mechanisms. An unauthorized user can bypass security checks to perform actions that should be restricted to administrators or specific users. This could lead to unauthorized modifications of directory listings or disruption of the directory service.
Technical details
The Business Directory plugin for WordPress (versions <= 6.4.23) is vulnerable to broken access control due to missing authorization checks (CWE-862). This allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The vulnerability is triggered via network requests that lack proper nonce or permission validation. Successful exploitation can result in unauthorized data modification or partial loss of availability. The issue is resolved in version 6.4.24.
Affected products
- Strategy11 Team Business Directory <= 6.4.23
Timeline
- 2026-04-25: other: Reported by John Umoru
- 2026-06-29: disclosed: NVD and Patchstack publication date
- 2026-06-29: patched: Version 6.4.24 released