Skip to content

Add CVE-2026-2576 WordPress Business Directory Plugin SQL Injection#15386

Open
stranger00135 wants to merge 6 commits intoprojectdiscovery:mainfrom
stranger00135:add-cve-2026-2576
Open

Add CVE-2026-2576 WordPress Business Directory Plugin SQL Injection#15386
stranger00135 wants to merge 6 commits intoprojectdiscovery:mainfrom
stranger00135:add-cve-2026-2576

Conversation

@stranger00135
Copy link

@stranger00135 stranger00135 commented Feb 18, 2026

CVE-2026-2576 — WordPress Business Directory Plugin <= 6.4.21 SQL Injection

Time-based blind SQL injection via the payment parameter array in the checkout workflow.

Root Cause

In class-db-query-set.php, the payment data is processed without proper escaping before being passed to SQL operations in the checkout workflow.

✅ Verified — True Positive

Environment: WordPress 6.7.1 + Business Directory Plugin 6.4.21
Verification: Confirmed SQL injection with time delay (6+ seconds)
Success Rate: 100% (multiple test vectors confirmed)

📊 Enhanced Metadata (Updated 2026-02-19)

  • EPSS Score: 0.00071 (21.59th percentile)
  • CPE: cpe:2.3:a:strategy11:business_directory_plugin:*:*:*:*:*:wordpress:*:*
  • Shodan Query: http.body:"business-directory-plugin"
  • FOFA Query: body="business-directory-plugin"
  • Detection: 3 matchers with condition: and (duration-based, body keywords, status codes)

References

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments