Junglewise Threat Intelligence

CVE-2026-84758: Business Directory Plugin broken access control

CVE-2026-84758 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Executive brief

The Business Directory Plugin is a WordPress plugin used to create and manage business listings and directories on WordPress sites. An unauthenticated attacker can bypass access controls to view or perform actions they should not be permitted to access, such as viewing other users' sensitive business information or manipulating directory data. This exposes customer data and undermines the integrity of the business directory functionality.

Technical details

The vulnerability is a broken access control issue in the Business Directory Plugin versions 6.4.26 and earlier, affecting unauthenticated users (CVSS 6.5). The plugin fails to properly enforce authorization checks on certain pages or actions, allowing attackers without authentication to access restricted functionality and data. No specific component or root cause is detailed in the advisory, but the attack is network-accessible and requires no authentication or user interaction. The vulnerability has been patched in version 6.4.27 and later; affected site administrators should update immediately.

Affected products

  • WPTasty Business Directory Plugin 6.4.26 and earlier

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Fixed in version 6.4.27

References