WordPress security by component
Connections Business Directory
Plugin description
Connections Business Directory is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jan 25, 2025; the highest CVE/CNA score is 10.
Plugin slug:
connectionsLatest vulnerability
CVE-2024-12885: Connections Business Directory: Arbitrary file deletion
Connections Business Directory is affected by arbitrary file deletion. Exploitation requires at least administrator-level access. A successful request can remove files outside the intended scope and may make the site unavailable.
| Safe version |
|
||
|---|---|---|---|
| Jan 25, 2025 |
CVE-2024-12885
Connections Business Directory: Arbitrary file deletion
Connections Business Directory is affected by arbitrary file deletion. Exploitation requires at least administrator-level access. A successful request can remove files outside the intended scope and may make the site unavailable.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 26, 2023 |
CVE-2023-29437
Connections: Cross-site scripting
Connections is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 16, 2017 |
CVE-2016-0770
Connections: Cross-site scripting
Connections is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jan 12, 2013 |
CVE-2011-5254
Connections: A security weakness
Connections is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE10.0
NVD10.0
|