Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57326 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-07-01 6.5 Medium
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
CVE-2026-57328 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-07-01 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
CVE-2026-57339 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-07-01 6.6 Medium
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
CVE-2023-5527 2 Businessdirectoryplugin, Strategy11team 2 Business Directory, Business Directory Plugin 2026-04-08 7.4 High
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.