Plugin Vulnerability Hub
Plugin 7 known issues Latest disclosed Jan 24, 2025

Connections Business Directory Vulnerabilities

Review known vulnerability records for the WordPress plugin Connections Business Directory (`connections`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2024-12885, CVE-2023-29437 and CVE-2021-24794, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
7
High or Critical
1
Patch Coverage
100%
Last Updated
Jan 25, 2025
Priority CVE Quick Links

Fast paths into Connections Business Directory CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
6
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Connections Business Directory so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
7 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 1 high severity finding.
Recent CVEs
CVE-2024-12885, CVE-2023-29437 and CVE-2021-24794
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Connections Business Directory

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: No CVE-2024-12885
CVE-2024-12885: Connections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory Deletion

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attac...

Published
Jan 24, 2025
Patched Release
Not published
Affected Versions
Versions up to 10.4.66
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2023-29437
CVE-2023-29437: Connections Business Directory <= 10.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Connections Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'connections' and 'upcoming_list' shortcodes in versions up to, and including, 10.4.36 due to insufficient input sanitization and output escaping. This makes it possible f...

Published
Apr 06, 2023
Patched Release
10.4.37
Affected Versions
Versions up to 10.4.36
Next Step
Update to 10.4.37 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24794
CVE-2021-24794: Connections Business Directory <= 10.4.2 - Admin+ Stored Cross-Site Scripting

The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

Published
Sep 28, 2021
Patched Release
10.4.3
Affected Versions
Versions before 10.4.3
Next Step
Update to 10.4.3 or newer if supported.
Plugin High Patched: Yes CVE-2020-36503
CVE-2020-36503: Connections Business Directory <= 9.6 - Authenticated CSV Injection

The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

Published
May 29, 2020
Patched Release
9.7
Affected Versions
Versions up to 9.6
Next Step
Update to 9.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2016-0770
CVE-2016-0770: Connections Business Directory < 8.5.9 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.

Published
Feb 01, 2016
Patched Release
8.5.9
Affected Versions
Versions before 8.5.9
Next Step
Update to 8.5.9 or newer if supported.
Plugin Medium Patched: Yes
Connections Business Directory < 0.7.9.4 - Cross-Site Scripting

The Connections Business Directory for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 0.7.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

Published
Feb 20, 2014
Patched Release
0.7.9.4
Affected Versions
Versions before 0.7.9.4
Next Step
Update to 0.7.9.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2011-5254
CVE-2011-5254: Connections Business Directory < 0.7.1.6 - Authorization Bypass

The Connections plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 0.7.1.5 due to insufficient authorization checks.

Published
Dec 29, 2011
Patched Release
0.7.1.6
Affected Versions
Versions up to 0.7.1.5
Next Step
Update to 0.7.1.6 or newer if supported.