CVE-2025-64219

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.18.
Configurations

No configuration.

History

20 Jan 2026, 15:18

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de falta de autorización en el plugin de directorio de negocios Strategy11 Team Business Directory permite la explotación de niveles de seguridad de control de acceso mal configurados. Este problema afecta a Business Directory: desde n/a hasta menor igual que 6.4.18.
References
  • {'url': 'https://vdp.patchstack.com/database/Wordpress/Plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-18-broken-access-control-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-18-broken-access-control-vulnerability?_s_id=cve -

13 Nov 2025, 11:17

Type Values Removed Values Added
References
  • {'url': 'https://vdp.patchstack.com/database/Wordpress/Plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-18-broken-access-control-vulnerability', 'source': 'audit@patchstack.com'}
  • () https://vdp.patchstack.com/database/Wordpress/Plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-18-broken-access-control-vulnerability?_s_id=cve -

29 Oct 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

29 Oct 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-29 09:15

Updated : 2026-01-20 15:18


NVD link : CVE-2025-64219

Mitre link : CVE-2025-64219

CVE.ORG link : CVE-2025-64219


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization