CVE-2024-12885: Connections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory Deletion
The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server and all their content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12885?
CVE-2024-12885 is considered a high severity vulnerability due to the potential for arbitrary directory deletion.
How do I fix CVE-2024-12885?
To fix CVE-2024-12885, update the Connections Business Directory plugin to version 10.4.67 or later.
Who is affected by CVE-2024-12885?
All users of the Connections Business Directory plugin for WordPress versions up to and including 10.4.66 are affected by CVE-2024-12885.
What type of vulnerability is CVE-2024-12885?
CVE-2024-12885 is an arbitrary directory deletion vulnerability caused by insufficient file path validation.
Can CVE-2024-12885 be exploited remotely?
CVE-2024-12885 requires authenticated access, meaning only authenticated attackers can exploit this vulnerability.