CVE-2024-12885
MEDIUMConnections Business Directory <10.4.66 - Path Traversal
Title source: llmDescription
The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server and all their content.
References (2)
Core 2
Core References
Scores
CVSS v3
6.5
EPSS
0.0053
EPSS Percentile
40.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
shazahm1hotmailcom/Connections Business Directory
< 10.4.66
Published
Jan 25, 2025
Tracked Since
Feb 18, 2026