plugin

Connections Vulnerabilities

16 known security issues reported for the Connections WordPress plugin. Most recent disclosed Jan 25, 2025.

1 high 6 medium

Running Connections on your site? Check whether your installed version is affected.

Scan your site free

Connections Business Directory [connections] <= 10.4.66 (unfixed + closed)

unknown

[en] The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level acce...

Affected:
up to 10.4.66
Fix:
No patched version reported
Disclosed:
Jan 25, 2025

CVE-2024-12885 on NVD →

Connections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory Deletion

medium

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access an...

CVSS:
6.5
Affected:
up to 10.4.66
Fix:
No patched version reported
Disclosed:
Jan 24, 2025

CVE-2024-12885 on NVD →

Connections Business Directory [connections] < 10.4.37 (closed)

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions.

Affected:
up to 10.4.37
Fixed in:
10.4.37
Disclosed:
Jun 26, 2023

CVE-2023-29437 on NVD →

Connections Business Directory <= 10.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Connections Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'connections' and 'upcoming_list' shortcodes in versions up to, and including, 10.4.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...

CVSS:
5.4
Affected:
up to 10.4.36
Fixed in:
10.4.37
Disclosed:
Apr 6, 2023

CVE-2023-29437 on NVD →

Connections Business Directory [connections] < 10.4.3 (closed)

unknown

[en] The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

Affected:
up to 10.4.3
Fixed in:
10.4.3
Disclosed:
Nov 1, 2021

CVE-2021-24794 on NVD →

Connections Business Directory [connections] < 9.7 (closed)

unknown

[en] The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

Affected:
up to 9.7
Fixed in:
9.7
Disclosed:
Nov 1, 2021

CVE-2020-36503 on NVD →

Connections Business Directory <= 10.4.2 - Admin+ Stored Cross-Site Scripting

medium

The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 10.4.3
Fixed in:
10.4.3
Disclosed:
Sep 28, 2021

CVE-2021-24794 on NVD →

Connections Business Directory <= 9.6 - Authenticated CSV Injection

high

The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

CVSS:
7.3
Affected:
up to 9.6
Fixed in:
9.7
Disclosed:
May 29, 2020

CVE-2020-36503 on NVD →

Connections Business Directory [connections] < 8.5.9 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.

Affected:
up to 8.5.9
Fixed in:
8.5.9
Disclosed:
Mar 16, 2017

CVE-2016-0770 on NVD →

Connections Business Directory < 8.5.9 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.

CVSS:
6.1
Affected:
up to 8.5.9
Fixed in:
8.5.9
Disclosed:
Feb 1, 2016

CVE-2016-0770 on NVD →

Connections Business Directory [connections] < 0.7.9.4 (closed)

unknown

This plugin is prone to a Pagination URL H&ling XSS vulnerability. Update the plugin.

Affected:
up to 0.7.9.4
Fixed in:
0.7.9.4
Disclosed:
Aug 1, 2014

Connections Business Directory < 0.7.9.4 - Cross-Site Scripting

medium

The Connections Business Directory for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 0.7.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 0.7.9.4
Fixed in:
0.7.9.4
Disclosed:
Feb 20, 2014

Connections Business Directory [connections] < 0.7.9.4 (closed)

unknown

The Connections Business Directory for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 0.7.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 0.7.9.4
Fixed in:
0.7.9.4
Disclosed:
Feb 20, 2014

Connections Business Directory [connections] < 0.7.1.6 (closed)

unknown

[en] Unspecified vulnerability in the Connections plugin before 0.7.1.6 for WordPress has unknown impact and attack vectors.

Affected:
up to 0.7.1.6
Fixed in:
0.7.1.6
Disclosed:
Jan 12, 2013

CVE-2011-5254 on NVD →

Connections Business Directory < 0.7.1.6 - Authorization Bypass

medium

The Connections plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 0.7.1.5 due to insufficient authorization checks.

CVSS:
6.1
Affected:
up to 0.7.1.5
Fixed in:
0.7.1.6
Disclosed:
Dec 29, 2011

CVE-2011-5254 on NVD →

Connections Business Directory [connections] < 0.7.9.4 (closed)

unknown

The Connections Business Directory WordPress plugin was affected by a Pagination URL H&amp;ling XSS security vulnerability.

Affected:
up to 0.7.9.4
Fixed in:
0.7.9.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database