What is CVE-2026-61959?
CVE-2026-61959 is a Subscriber Cross Site Scripting (XSS) vulnerability found in the Business Directory plugin for versions <= 6.4.24. This flaw could allow users with subscriber-level permissions to inject and execute malicious scripts. It is strongly recommended to update the plugin to the latest available version immediately.
Azərbaycanca: CVE-2026-61959, Business Directory plagininin 6.4.24 və daha əvvəlki versiyalarında aşkar edilmiş Subscriber Cross Site Scripting (XSS) zəifliyidir. Bu zəiflik aşağı səlahiyyətli istifadəçilərə zərərli skriptləri icra etməyə imkan verə bilər. Plagindən istifadə edən sayt sahiblərinə dərhal plaqini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Business Directory plugin are affected by CVE-2026-61959?
This vulnerability affects versions 6.4.24 and earlier of the Business Directory plugin.
How to mitigate the CVE-2026-61959 vulnerability?
Site owners using the plugin should immediately update the Business Directory plugin to the latest available version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.