VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67596

CVE-2025-67596

Description

Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Cross Site Request Forgery.This issue affects Business Directory: from n/a through <= 6.4.19.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) in the Business Directory plugin for WordPress allows attackers to force privileged users into executing unwanted actions.

The Business Directory plugin for WordPress (versions up to and including 6.4.19) contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw arises from insufficient verification of the origin of requests, allowing an attacker to craft malicious links that, when clicked by an authenticated administrator or other privileged user, perform unauthorized actions on the victim's behalf [1].

The exploitation requires user interaction — a privileged user must click a crafted link or visit a malicious page while logged into the WordPress admin area. No authentication is needed for the attacker themselves, but the victim must have an active session with sufficient privileges [1]. This attack vector is commonly used in mass exploitation campaigns targeting multiple websites simultaneously [1].

If successfully exploited, an attacker can force the victim to perform unintended actions, such as modifying plugin settings, deleting directory entries, or other administrative operations the victim is authorized to perform. The CVSS score of 4.3 (Medium) reflects the requirement for user interaction and the need for a privileged victim [1].

The vendor has released version 6.4.20 which resolves the vulnerability. The recommended mitigation is to update to this latest version; Patchstack users can enable auto-update for affected plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.