Unauthenticated Insecure Direct Object References in Business Directory Plugin by WordPress
CVE-2026-84769
6.5MEDIUM
What is CVE-2026-84769?
The Business Directory Plugin for WordPress is susceptible to unauthenticated Insecure Direct Object References (IDOR) that may allow attackers to access sensitive information or resources without proper authorization. The vulnerability exists in versions up to 6.4.26, enabling unauthorized users to manipulate direct object references to obtain information they should not have access to, potentially compromising the integrity of user data.
Affected Version(s)
Business Directory <= 6.4.26