CVE-2020-36503: Connections-Pro Connections Business Directory
High severity, CVSS 8.0. EPSS: 1.2% chance of exploitation in the next 30 days.
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
Affected products
- Connections-Pro Connections Business Directory: from 0.7.3.2, up to and including 9.6
Published 2021-11-01. Last modified 2026-06-17.