CVE-2025-31918: WordPress Simple Business Directory Pro plugin < 15.6.9 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through 15.4.8.
Other sources
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31918?
CVE-2025-31918 is classified as a high-severity privilege escalation vulnerability.
How do I fix CVE-2025-31918?
To fix CVE-2025-31918, update the Simple Business Directory Pro plugin to a version higher than 15.4.8.
Who is affected by CVE-2025-31918?
CVE-2025-31918 affects users of QuantumCloud's Simple Business Directory Pro and WordPress versions up to 15.4.8.
What type of vulnerability is CVE-2025-31918?
CVE-2025-31918 is an incorrect privilege assignment vulnerability that allows for privilege escalation.
What can attackers gain from exploiting CVE-2025-31918?
Attackers exploiting CVE-2025-31918 can gain elevated permissions, potentially allowing them to modify or delete data.