CVE-2026-84769: WordPress Business Directory plugin <= 6.4.26 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
Affected Software
1 affected component
WordPress Business Directory plugin<=6.4.26
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Business Directory pluginto a version that resolves this vulnerability.Fixed in 6.4.27
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require a WordPress account or other credentials?
No. The vulnerability is unauthenticated, and the CVSS vector indicates no privileges or user interaction are required.
2
How can I determine whether my site is affected?
Check the installed version of the WordPress Business Directory plugin. Versions 6.4.26 and earlier are identified as affected.
3
What is the expected impact if exploited?
The reported CVSS metrics indicate low confidentiality and integrity impact, with no availability impact.