The Business Directory Plugin – Easy Listing Directories for WordPress (Business Directory Plugin) is vulnerable to time-based SQL injection via the 'payment' request parameter in all versions up to and including 6.4.2. The issue is caused by insufficient escaping of user-supplied input and lack of proper SQL query preparation (e.g., missing parameterization), allowing an unauthenticated attacker to append/manipulate SQL in an existing query and leverage time-based techniques to infer and extract sensitive information from the WordPress database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained research lab and proof-of-concept for CVE-2026-2576, an unauthenticated time-based blind SQL injection in the Business Directory Plugin for WordPress <= 6.4.21. It is not part of a larger exploit framework. The repository contains: (1) a detailed README explaining root cause, trigger path, and exploitation logic; (2) a Docker lab that provisions MySQL, WordPress 6.4, phpMyAdmin, and a setup container; (3) a Bash setup script that installs WordPress, downloads and activates the vulnerable plugin version 6.4.21, creates the Business Directory page, seeds a payment record with payment_key seed-pay-001, and creates test users; (4) init-db.sql, which seeds a lab-only secrets table for extraction testing; (5) poc.py, the main exploit script; and (6) patch_diff.py, a helper utility that downloads plugin versions 6.4.21 and 6.4.22 and diffs them to identify the patch. The main exploit capability is in cve-2026-2576-lab/poc/poc.py. It builds unauthenticated GET requests to the WordPress checkout endpoint using the vulnerable parameter pattern payment[]=..., specifically /?page_id=<id>&wpbdp_view=checkout&payment[]=<payload>. The payload closes the IN() clause and appends a MySQL IF(condition,SLEEP(N),0) expression followed by a comment, creating a timing oracle. The script measures response time to determine whether injected SQL conditions are true or false. It supports detection and data extraction workflows, including extracting the current database name, enumerating tables, dumping table contents, and running custom SQL extraction logic. The extraction routine uses binary search over ASCII values and parallel threads to speed up character-by-character inference. The exploit is operational rather than a simple PoC because it includes a working payload, configurable target parameters, timing thresholds, concurrency, and multiple extraction modes. However, it is still a research-oriented tool with a hardcoded exploitation pattern rather than a generalized framework module. The repository also exposes several fingerprintable endpoints and artifacts, especially the vulnerable web route, local lab URLs, plugin download URLs, Docker service hostnames, and mounted file paths. Overall, the repository's purpose is to reproduce, validate, and study the SQL injection vulnerability in a controlled environment and to demonstrate practical blind extraction against the affected WordPress plugin.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.