N/A
2026-02-17< 6.4.22
Business Directory Plugin <= 6.4.21 - Unauthenticated SQL Injection via payment Parameter
Minimum safe version
6.4.22
Update to 6.4.22 or later to address 17 fixable vulnerabilities
Business Directory Plugin <= 6.4.21 - Unauthenticated SQL Injection via payment Parameter
Business Directory Plugin <= 6.4.20 - Missing Authorization to Unauthenticated Arbitrary Listing Modification
CVE-2025-64630
CVE-2025-67596
CVE-2025-64219
CVE-2024-13887
CVE-2023-5527
CVE-2024-4443
WordPress Business Directory Plugin Plugin <= 6.3.9 is vulnerable to Broken Access Control
CVE-2023-5803
WordPress Business Directory Plugin <= 4.1.14 - Authenticated PHP Object Injection Vulnerability
CVE-2021-24179
CVE-2021-24178
CVE-2021-24251
CVE-2021-24250
CVE-2021-24249
CVE-2021-24248