SQL Injection Vulnerability in CMSJunkie's WordPress Business Directory Plugin
CVE-2025-24759
9.3CRITICAL
What is CVE-2025-24759?
An SQL injection vulnerability has been identified in CMSJunkie's WP-BusinessDirectory plugin for WordPress. This flaw permits blind SQL injection, potentially allowing attackers to manipulate the database query and gain unauthorized access to sensitive data. The vulnerability affects versions of the plugin from its initial release up to 3.1.3, emphasizing the need for prompt updates to secure web applications against such critical threats.
Affected Version(s)
WP-BusinessDirectory <= 3.1.3
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Martino Spagnuolo (r3verii) (Patchstack Alliance)