CVE-2016-0770
MEDIUMWordPress <8.5.9 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.
References (4)
Scores
CVSS v3
6.1
EPSS
0.0059
EPSS Percentile
68.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
zahmit_design/connections_business_directory_plugin
< 8.5.8
n/a/n/a
Timeline
Published
Mar 16, 2017
Tracked Since
Feb 18, 2026