Executive brief
A critical security vulnerability has been identified in the Simple Business Directory Pro plugin for WordPress, which is used to create and manage business listings. This flaw allows unauthorized individuals to inject malicious commands into the website's database. If exploited, an attacker could gain access to sensitive information, potentially leading to data theft or disruption of the directory service.
Technical details
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in the quantumcloud Simple Business Directory Pro plugin (simple-business-directory-pro). The flaw is present in versions up to and including 15.9.4. This is a remote, unauthenticated vulnerability (AV:N/AC:L/PR:N/UI:N) that allows an attacker to execute arbitrary SQL queries against the backend database. Successful exploitation can lead to high confidentiality impact and limited availability impact. Users are advised to upgrade to version 15.9.5 or later to mitigate this risk.
Affected products
- quantumcloud Simple Business Directory Pro <= 15.9.4
Timeline
- 2026-07-13: advisory: Published by NVD and Patchstack
- 2026-07-13: disclosed