Unauthenticated Access Control Flaw in Business Directory Plugin by WordPress
CVE-2026-84758

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84758?

The Business Directory Plugin for WordPress, in versions up to 6.4.26, is susceptible to an unauthenticated broken access control vulnerability. This flaw allows attackers to bypass authentication measures and gain unauthorized access to sensitive features of the plugin, leading to potential data exposure and manipulation. Website administrators using the affected versions are urged to update promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

Business Directory <= 6.4.26

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.