Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Business Directory Plugin for WordPress: Unauthorized Changes Possible

CVE-2026-1656
Summary

The Business Directory Plugin for WordPress, used by many sites, has a security flaw that lets anyone modify listing information without needing a password. This could lead to fake or incorrect business listings. Update to the latest version to fix this issue.

Original title
The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and including, 6.4.20. This makes it possible for unaut...
Original description
The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and including, 6.4.20. This makes it possible for unauthenticated attackers to modify arbitrary listings, including changing titles, content, and email addresses, by directly referencing the listing ID in crafted requests to the wpbdp_ajax AJAX action.
nvd CVSS3.1 5.3
Vulnerability type
CWE-862 Missing Authorization
Published: 18 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026