CVE-2016-0770: XSS
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0770?
The severity of CVE-2016-0770 is classified as medium due to its potential to allow remote attackers to execute arbitrary web scripts.
How do I fix CVE-2016-0770?
To fix CVE-2016-0770, upgrade the Connections Business Directory plugin to version 8.5.9 or later.
What software is affected by CVE-2016-0770?
CVE-2016-0770 affects the Connections Business Directory plugin for WordPress versions prior to 8.5.9.
What type of vulnerability is CVE-2016-0770?
CVE-2016-0770 is a cross-site scripting (XSS) vulnerability.
Can CVE-2016-0770 affect my WordPress site?
Yes, if you are using an affected version of the Connections Business Directory plugin, your WordPress site may be vulnerable to CVE-2016-0770.