Junglewise Threat Intelligence

CVE-2026-84769: WPTasty Business Directory plugin IDOR

CVE-2026-84769 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Executive brief

Business Directory is a popular WordPress plugin for creating online business listings and directories. An unauthenticated attacker can exploit Insecure Direct Object References (IDOR) to view and potentially modify other users' business directory data by manipulating object IDs in URLs—exposing private business information without authentication or authorization.

Technical details

This is an Insecure Direct Object References (IDOR) vulnerability in the Business Directory WordPress plugin versions 6.4.26 and earlier. The vulnerable component fails to properly validate access controls on user-accessible objects, allowing attackers to enumerate and access sensitive business data by modifying object identifiers in URL parameters. No authentication is required to exploit this vulnerability—an attacker can simply change numeric IDs in the URL to access arbitrary business directory entries, exposing private business information. The vulnerability was reported on 21 Aug 2026 and patched in version 6.4.27 on 3 Sep 2026. This attack is classified under OWASP Top 10 A1: Broken Access Control.

Affected products

  • WPTasty Business Directory <= 6.4.26

Timeline

  • 2026-09-03: disclosed: CVE published on NVD
  • 2026-09-03: patched: Patched in version 6.4.27
  • 2026-08-21: other: Initially reported to vendor

References