Simple Business Directory Pro < 15.6.9 - Unauthenticated Privilege Escalation
2025-08-19 00:00
João Pedro Soares de AlcântaraStrategic Overview
StatusPatched in 15.6.9
Affected PluginSimple Business Directory Pro
Affected Version
< 15.6.9CVSS9.8Critical
CVE
CVE-2025-53580Vulnerability Overview
The Simple Business Directory Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 15.6.9 (exclusive). This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Technical Analysis
REMEDIATION: Update to version 15.6.9, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C