CVE-2020-36503: Connections-Pro Connections Business Directory

High severity, CVSS 8.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

Affected products

  • Connections-Pro Connections Business Directory: from 0.7.3.2, up to and including 9.6

Published 2021-11-01. Last modified 2026-06-17.