Back

HIGH

WordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerability

Published Sep 30, 2026

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.

Affected products

Remediation

Vendor solution

Update the WordPress Business Directory plugin to the latest available version (at least 6.4.28).

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Sep 30, 2026
Updated Sep 30, 2026
Reserved Jul 13, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 30, 2026
Red Hat
Severity n/a
Public date n/a