← Back

Business Directory Plugin Easy Listing Directories

business_directory_plugin_-_easy_listing_directories

Vendor: Strategy11 • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Strategy11
1Business Directory Plugin Easy Listing Directories
Jun 17, 2026
May 6, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitr...Show more
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)Show less
1Strategy11
1Business Directory Plugin Easy Listing Directories
Jun 17, 2026
May 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripti...Show more
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.Show less
1Strategy11
1Business Directory Plugin Easy Listing Directories
Jun 17, 2026
May 6, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files,...Show more
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etcShow less
1Strategy11
1Business Directory Plugin Easy Listing Directories
Jun 17, 2026
May 6, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrat...Show more
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCEShow less
1Strategy11
1Business Directory Plugin Easy Listing Directories
Jun 17, 2026
May 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. A...Show more
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.Show less
1Strategy11
1Business Directory Plugin Easy Listing Directories
Jun 17, 2026
May 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or d...Show more
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.Show less