CVE-2025-64630: WordPress Business Directory plugin <= 6.4.19 - Broken Access Control vulnerability
Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64630?
The severity of CVE-2025-64630 is considered to be medium due to its potential to allow unauthorized access to sensitive features.
How do I fix CVE-2025-64630?
You can fix CVE-2025-64630 by updating the Strategy11 Business Directory plugin to version 6.4.20 or later.
What are the potential impacts of CVE-2025-64630?
Exploiting CVE-2025-64630 may allow attackers to gain unauthorized access to restricted functionalities of the business directory.
Which versions are affected by CVE-2025-64630?
CVE-2025-64630 affects all versions of the Strategy11 Business Directory plugin from n/a through 6.4.19.
Who is the vendor for CVE-2025-64630?
The vendor for CVE-2025-64630 is Strategy11, which maintains the Business Directory plugin.