CVE-2023-29437: WordPress Connections Business Directory Plugin <= 10.4.36 is vulnerable to Cross Site Scripting (XSS)
Published Jun 26, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions.
Affected Software
1 affected component
Connections-pro Connections Business Directory Wordpress<=10.4.36
Remediation
Information
Update to 10.4.37 or a higher version
Event History
Jun 26, 2023
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-29437?
CVE-2023-29437 is classified as a high severity vulnerability due to its potential for exploitation via stored cross-site scripting.
2
How do I fix CVE-2023-29437?
To fix CVE-2023-29437, update the Connections Business Directory plugin to version 10.4.37 or later.
3
What systems are affected by CVE-2023-29437?
CVE-2023-29437 affects versions of the Connections Business Directory plugin up to and including 10.4.36.
4
What type of vulnerability is CVE-2023-29437?
CVE-2023-29437 is a stored cross-site scripting (XSS) vulnerability that can be exploited by authenticated users.
5
Who is the vendor for CVE-2023-29437?
The vendor for CVE-2023-29437 is Connections Pro, the developer of the Connections Business Directory plugin.