Sceawere

Vulnerability Detail

CVE-2026-94173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Business Directory IDOR Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
Strategy11 Team
Product
Business Directory
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-30T13:17:25.263Z",
  "pubdate": "2026-09-30T13:17:25.263Z",
  "executiveSummary": "The Business Directory plugin for WordPress, in versions 6.4.27 and below, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows an authenticated attacker with contributor-level privileges to bypass intended access controls and perform unauthorized operations on objects within the plugin.\nBy manipulating direct object references—typically identifiers passed within HTTP requests—an attacker can access, modify, or delete sensitive business directory listings or related data that should be restricted to administrators or the original listing owners.\nThe risk implication is a potential loss of data integrity and unauthorized information disclosure within the business directory management interface.\nSuccessful exploitation requires authenticated access to the application as a contributor; however, it does not require higher administrative privileges, making it a significant privilege escalation and unauthorized access concern.\nThe flaw stems from insufficient authorization checks on the server side when processing requests involving object IDs, failing to verify that the requesting user has the necessary permissions to interact with the target resource.",
  "technicalDetails": "The vulnerability resides within the request handling logic of the Business Directory plugin. The root cause is a failure to properly implement authorization validation for objects referenced in HTTP requests.\nSpecifically, the plugin processes administrative or management actions based on parameters supplied by the client, such as IDs for directory listings, without cross-referencing these IDs against the current user's identity or authorization context.\nWhen a user with contributor-level privileges submits a request (e.g., via POST or GET parameters) to modify or interact with a directory object, the application identifies the object through a direct reference (e.g., an ID parameter in the URL or request body).\nThe application backend proceeds to execute the requested action upon the specified ID without verifying if the authenticated contributor holds the required permissions to perform the action on that specific object.\nThe attack flow proceeds as follows: 1. An attacker with a contributor account authenticates to the WordPress site. 2. The attacker identifies the endpoint used for managing directory listings (e.g., modifying, updating, or deleting). 3. The attacker observes the request structure, identifying parameters that pass object identifiers. 4. The attacker crafts a malicious request targeting an object ID that they are not authorized to access or modify. 5. The server processes the request, recognizing the attacker is authenticated, but failing to perform an access control check against the specific object ID provided. 6. The action is executed, resulting in unauthorized modification or deletion of the target resource.\nThis vulnerability is restricted to authenticated users with at least contributor privileges. It is exploitable over the network through standard HTTP/HTTPS channels. The post-exploitation impact includes the ability to alter directory content, potentially leading to data destruction, unauthorized information disclosure, or manipulation of business data displayed to end-users.\nThe flaw affects versions 6.4.27 and earlier. The vulnerable component is the server-side code responsible for handling management actions for directory listings, which lacks robust validation of user permissions relative to the object ID in the request context."
}
CVE-2026-94173: Business Directory IDOR Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere