Path Traversal Vulnerability in CMSJunkie - WP-BusinessDirectory Plugin
CVE-2025-32629

8.6HIGH

Key Information:

Vendor
Cmsjunkie - WordPress Business Directory Plugins
Status
WP-businessdirectory
Vendor
CVE Published:
11 April 2025

Summary

A Path Traversal vulnerability exists in the CMSJunkie WP-BusinessDirectory plugin that enables attackers to bypass directory restrictions. This flaw can allow unauthorized access to the file system, potentially leading to arbitrary file deletion and other serious security implications. It is essential for users of the WP-BusinessDirectory plugin, specifically versions up to and including 3.1.2, to take immediate action to mitigate the risks posed by this vulnerability.

Affected Version(s)

WP-BusinessDirectory <= 3.1.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.