CVE-2026-84758: WordPress Business Directory plugin <= 6.4.26 - Broken Access Control vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
Affected Software
1 affected component
WordPress Business Directory plugin<=6.4.26
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Business Directory pluginto a version that resolves this vulnerability.Fixed in 6.4.27
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any prior privileges to attempt exploitation over the network.
2
What security impact is indicated?
The reported impact is limited to integrity and availability; confidentiality impact is listed as none. The severity is medium with a CVSS score of 6.5.
3
Which plugin versions are affected?
Business Directory plugin versions up to and including 6.4.26 are identified as affected.