Pricing
Case studies
Login
Start trial
Business Directory
Strategy11 Team
Developer
6.4.22
Latest version
10,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
14 patched
3 Mitigation rules
Unauthenticated SQL Injection via payment Parameter vulnerability
<= 6.4.21
18/02/2026
Missing Authorization to Unauthenticated Arbitrary Listing Modification vulnerability
<= 6.4.20
18/02/2026
Broken Access Control vulnerability
<= 6.4.19
15/12/2025
Cross Site Request Forgery (CSRF) vulnerability
<= 6.4.19
03/12/2025
Broken Access Control vulnerability
<= 6.4.18
19/10/2025
Insecure Direct Object Reference to Listing Arbitrary Image Addition vulnerability
<= 6.4.14
12/03/2025
Authenticated CSV Injection vulnerability
<= 6.4.3
17/06/2024
Unauthenticated SQL Injection via listingfields Parameter vulnerability
<= 6.4.2
22/05/2024
Broken Access Control vulnerability
<= 6.3.9
27/12/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 6.3.10
28/11/2023
Cross-Site Request Forgery (CSRF) vulnerability
<= 5.11.1
12/04/2021
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 5.11.1
12/04/2021
Arbitrary Listing Export vulnerability
<= 5.11.1
12/04/2021
Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE)
<= 5.10.1
11/04/2021