← WordPress Vulnerabilities
WordPress security by component

Business Directory

Business Directory is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jun 29, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: business-directory-plugin

CVE-2026-57339: Business Directory: A security weakness

Business Directory is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.4.23.

PublishedJun 29, 2026
Known safe version6.4.24
Safe version
Jun 29, 2026 CVE-2026-57339
Business Directory: A security weakness
Business Directory is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.4.23.
6.4.24
CVE6.5
NVDPending
Jun 29, 2026 CVE-2026-57328
Business Directory: Cross-site scripting
Business Directory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 6.4.22.
6.4.23
CVE6.5
NVDPending
Jun 29, 2026 CVE-2026-57326
Business Directory: Cross-site scripting
Business Directory is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 6.4.22.
6.4.23
CVE6.1
NVDPending
Feb 18, 2026 CVE-2026-1656
Business Directory: A security weakness
Business Directory is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 18, 2026 CVE-2026-2576
Business Directory Plugin – Easy Listing Directories for: SQL injection
Business Directory Plugin – Easy Listing Directories for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Dec 16, 2025 CVE-2025-64630
Business Directory: A security weakness
Business Directory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVDPending
Dec 09, 2025 CVE-2025-67596
Business Directory: Cross-site request forgery
Business Directory is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Oct 29, 2025 CVE-2025-64219
Business Directory: A security weakness
Business Directory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 18, 2024 CVE-2023-5527
Business Directory Plugin: A security weakness
Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.4
NVD8.0
Jun 14, 2024 CVE-2023-51516
Business Directory Plugin: A security weakness
Business Directory Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
May 22, 2024 CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for: SQL injection
Business Directory Plugin – Easy Listing Directories for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD7.5
Nov 30, 2023 CVE-2023-5803
Business Directory Plugin – Easy Listing Directories for WordPress: Cross-site request forgery
Business Directory Plugin – Easy Listing Directories for WordPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8