CVE-2025-67596: WordPress Business Directory plugin <= 6.4.19 - Cross Site Request Forgery (CSRF) vulnerability
Published Dec 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Cross Site Request Forgery.This issue affects Business Directory: from n/a through <= 6.4.19.
Affected Software
2 affected components
npm/business-directory-plugin<=6.4.19
Strategy11 Business Directory<=6.4.19
Event History
Dec 9, 2025
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67596?
CVE-2025-67596 has a critical severity level due to its potential for exploitation through Cross-Site Request Forgery.
2
How do I fix CVE-2025-67596?
To fix CVE-2025-67596, update the Business Directory plugin to version 6.4.20 or later.
3
What versions are affected by CVE-2025-67596?
CVE-2025-67596 affects Business Directory plugin versions from n/a up to and including 6.4.19.
4
What type of vulnerability is CVE-2025-67596?
CVE-2025-67596 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor associated with CVE-2025-67596?
The vendor associated with CVE-2025-67596 is Strategy11.