CVE-2025-64219: WordPress Business Directory plugin <= 6.4.18 - Broken Access Control vulnerability
Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.18.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64219?
CVE-2025-64219 is classified as a medium severity vulnerability due to its potential impact on sensitive data access.
How do I fix CVE-2025-64219?
To fix CVE-2025-64219, update the Strategy11 Business Directory plugin to the latest version beyond 6.4.18.
What kind of attacks can exploit CVE-2025-64219?
CVE-2025-64219 can be exploited through unauthorized access to restricted information due to misconfigured access controls.
Which versions of the plugin are affected by CVE-2025-64219?
Versions of the Strategy11 Business Directory plugin from an unknown release up to and including 6.4.18 are affected by CVE-2025-64219.
Is there a workaround for CVE-2025-64219?
While updating is the best approach, temporarily limiting user access permissions could serve as a workaround for CVE-2025-64219.