Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Business Directory Plugin – Easy Listing Directories for WordPress — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Business Directory Plugin – Easy Listing Directories for WordPress, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the Business Directory Plugin, a popular WordPress directory management tool, categorized under common weakness types such as Cross-Site Scripting and Injection flaws. The collection covers security advisories and reported incidents spanning from the plugin's early releases through recent updates, ensuring a comprehensive view of its historical security posture. Here, users can track vendor advisories to stay informed about patches, understand specific weakness classes affecting the software’s architecture, and look up the product’s detailed vulnerability history for compliance or risk assessment purposes. This resource is designed to help administrators, developers, and security researchers assess the potential risks associated with installing or maintaining this specific plugin. By consolidating disparate sources of information, the page provides a centralized reference point for evaluating the plugin’s track record regarding security disclosures. It does not offer real-time monitoring but rather serves as a static archive of confirmed issues. Users are encouraged to review the documented weaknesses to understand the nature of the exploits and the remediation steps taken by the maintainers. This information supports informed decision-making when selecting or updating WordPress extensions. The data reflects publicly available information and community reports, aiming to increase transparency and facilitate better security practices within the WordPress ecosystem.

Vendor: Business Directory Team

CVE IDTitleCVSSSeverityPublished
CVE-2026-1656 Business Directory Plugin <= 6.4.20 - Missing Authorization to Unauthenticated Arbitrary Listing Modification CWE-862 5.3 Medium2026-02-18
CVE-2026-2576 Business Directory Plugin <= 6.4.21 - Unauthenticated SQL Injection via payment Parameter CWE-89 7.5 High2026-02-18
CVE-2024-13887 Business Directory Plugin - Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image Addition CWE-639 5.3 Medium2025-03-13
CVE-2023-5527 Business Directory Plugin <= 6.4.3 - Authenticated (Author+) CSV Injection CWE-1236 7.4 High2024-06-18
CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter CWE-89 9.8 Critical2024-05-22
CVE-2023-5803 WordPress Business Directory Plugin Plugin <= 6.3.10 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-11-30
CVE-2021-24248 Business Directory Plugin < 5.11.1 - Authenticated PHP4 Upload to RCE CWE-434 7.2 -2021-05-05
CVE-2021-24249 Business Directory Plugin < 5.11.2 - Arbitrary Listing Export CWE-352 6.5 -2021-05-05
CVE-2021-24250 Business Directory Plugin < 5.11.2 - Authenticated Stored Cross-Site Scripting CWE-79 5.4 -2021-05-05
CVE-2021-24251 Business Directory Plugin < 5.11.2 - Arbitrary Payment History Update CWE-352 4.3 -2021-05-05
CVE-2021-24178 Business Directory Plugin < 5.11.1 - Arbitrary Add/Edit/Delete Form Field to Stored XSS CWE-352 8.1 -2021-05-05
CVE-2021-24179 Business Directory Plugin < 5.11 - Arbitrary File Upload to RCE CWE-352 8.8 -2021-05-05

All 12 known CVE vulnerabilities affecting Business Directory Plugin – Easy Listing Directories for WordPress with full Chinese analysis, references, and POCs where available.