Path Traversal Vulnerability in CMSJunkie - WP-BusinessDirectory Plugin
CVE-2025-32629
8.6HIGH
Key Information:
- Vendor
- Cmsjunkie - WordPress Business Directory Plugins
- Status
- WP-businessdirectory
- Vendor
- CVE Published:
- 11 April 2025
Summary
A Path Traversal vulnerability exists in the CMSJunkie WP-BusinessDirectory plugin that enables attackers to bypass directory restrictions. This flaw can allow unauthorized access to the file system, potentially leading to arbitrary file deletion and other serious security implications. It is essential for users of the WP-BusinessDirectory plugin, specifically versions up to and including 3.1.2, to take immediate action to mitigate the risks posed by this vulnerability.
Affected Version(s)
WP-BusinessDirectory <= 3.1.2
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)