CVE-2023-5527 HIGH

CVE-2023-5527: Business Directory Plugin <= 6.4.3 - Authenticated (Author+) CSV Injection

Vendor Strategy11Team
Product Business Directory Plugin – Easy Listing Directories for WordPress
Weakness CWE-1236
Published June 18, 2024
Last update April 8, 2026

CVSS base score

7.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Explanation of Vulnerability in Simple Terms

02Summary

The Business Directory Plugin for WordPress versions 6.4.3 and earlier contains a vulnerability that allows authenticated users with low privileges to read sensitive data, modify content, or disrupt site availability. The vulnerability affects the entire WordPress installation due to scope change. Site administrators should update to a version newer than 6.4.3 as soon as possible.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, or disrupt site availability across the WordPress installation.

Potential impact on your site

04Site Impact

Compromised user accounts or low-privilege attackers can access private data, alter posts/pages, or cause service disruption.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

June 18, 2024 CVE published
April 8, 2026 Record updated