๐Ÿ” CVE Alert

CVE-2026-86789

UNKNOWN 0.0

Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses. The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.

Vendor unknown
Product connections business directory
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown connections business directory

Be the first to know when new unknown vulnerabilities affecting unknown connections business directory are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Connections Business Directory
0 โ‰ค 10.4.67

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3514e2f9-4dda-45ae-80c0-c7caafcb7d8a/

Credits

Usama Arshad WPScan