CVE-2025-53580
9.8QuantumCloud · Simple Business Directory Pro
An incorrect privilege assignment vulnerability in the Simple Business Directory Pro WordPress plugin allows unauthenticated attackers to escalate privileges.
Executive summary
The Simple Business Directory Pro WordPress plugin is vulnerable to unauthorized privilege escalation, posing a critical risk of total site compromise.
Vulnerability
The plugin suffers from an incorrect privilege assignment (CWE-266) vulnerability. This flaw allows unauthenticated remote attackers to escalate their privileges, potentially gaining administrative access to the WordPress environment.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain full control over the WordPress site. Given the CVSS score of 9.8, this represents a critical risk that could lead to complete data exfiltration, unauthorized modification of content, or the installation of persistent backdoors, resulting in severe reputational damage and potential loss of intellectual property.
Remediation
Immediate Action: Update the Simple Business Directory Pro plugin to version 15.6.9 or later immediately.
Proactive Monitoring: Review WordPress user account logs for unexpected administrative account creation or unauthorized changes to user roles.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin-specific AJAX actions or privilege-related endpoints.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept repository exists on GitHub.
Analyst recommendation
This vulnerability is critical due to its potential for full administrative takeover without requiring prior authentication. Organizations utilizing this plugin must prioritize the update to version 15.6.9 to eliminate the risk of privilege escalation.