WordPress security by component
Business Directory
Plugin description
Business Directory is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jun 29, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
business-directory-pluginLatest vulnerability
CVE-2026-57339: Business Directory: A security weakness
Business Directory is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.4.23.
| Safe version |
|
||
|---|---|---|---|
| Jun 29, 2026 |
CVE-2026-57339
Business Directory: A security weakness
Business Directory is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.4.23.
|
6.4.24 |
CVE6.5
NVDPending
|
| Jun 29, 2026 |
CVE-2026-57328
Business Directory: Cross-site scripting
Business Directory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 6.4.22.
|
6.4.23 |
CVE6.5
NVDPending
|
| Jun 29, 2026 |
CVE-2026-57326
Business Directory: Cross-site scripting
Business Directory is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 6.4.22.
|
6.4.23 |
CVE6.1
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1656
Business Directory: A security weakness
Business Directory is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 18, 2026 |
CVE-2026-2576
Business Directory Plugin – Easy Listing Directories for: SQL injection
Business Directory Plugin – Easy Listing Directories for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Dec 16, 2025 |
CVE-2025-64630
Business Directory: A security weakness
Business Directory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Dec 09, 2025 |
CVE-2025-67596
Business Directory: Cross-site request forgery
Business Directory is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 29, 2025 |
CVE-2025-64219
Business Directory: A security weakness
Business Directory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 18, 2024 |
CVE-2023-5527
Business Directory Plugin: A security weakness
Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.4
NVD8.0
|
| Jun 14, 2024 |
CVE-2023-51516
Business Directory Plugin: A security weakness
Business Directory Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| May 22, 2024 |
CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for: SQL injection
Business Directory Plugin – Easy Listing Directories for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Nov 30, 2023 |
CVE-2023-5803
Business Directory Plugin – Easy Listing Directories for WordPress: Cross-site request forgery
Business Directory Plugin – Easy Listing Directories for WordPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|