SQL Injection Vulnerability in CMSJunkie's WordPress Business Directory Plugin
CVE-2025-24759

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 July 2025

What is CVE-2025-24759?

An SQL injection vulnerability has been identified in CMSJunkie's WP-BusinessDirectory plugin for WordPress. This flaw permits blind SQL injection, potentially allowing attackers to manipulate the database query and gain unauthorized access to sensitive data. The vulnerability affects versions of the plugin from its initial release up to 3.1.3, emphasizing the need for prompt updates to secure web applications against such critical threats.

Affected Version(s)

WP-BusinessDirectory <= 3.1.3

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martino Spagnuolo (r3verii) (Patchstack Alliance)
.
CVE-2025-24759 : SQL Injection Vulnerability in CMSJunkie's WordPress Business Directory Plugin