nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-1656 CVE-2026-1656
MEDIUM
Business Directory Plugin <= 6.4.20 - Missing Authorization to Unauthenticated Arbitrary Listing Modification
Record summary
CVE-2026-1656 has a selected CVSS score of 5.3 (medium).
Description
The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and including, 6.4.20. This makes it possible for unauthenticated attackers to modify arbitrary listings, including changing titles, content, and email addresses, by directly referencing the listing ID in crafted requests to the wpbdp_ajax AJAX action.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Business Directory Plugin – Easy Listing Directories for WordPressBrowse strategy11team / Business Directory Plugin – Easy Listing Directories for WordPressDefault status: unaffected | CVE List | Through 6.4.20 | affected |
References
5plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/business-directory-plugin/tags/6.4.20/includes/helpers/class-authenticated-listing-view.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/business-directory-plugin/trunk/includes/helpers/class-authenticated-listing-view.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3452627/business-directory-plugin/tags/6.4.21/includes/controllers/pages/class-submit-listing.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/f894ce75-168c-4baa-8cae-d2e7f1a0a9ab?source=cve