CVE-2026-86789
Received Received - Intake

Unauthenticated REST API Exposure in Connections Business Directory

Vulnerability report for CVE-2026-86789, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses. The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
connections_business_directory plugin to 10.4.67 (inc)
connections_business_directory plugin to 10.4.67 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Connections Business Directory WordPress plugin through version 10.4.67 has a vulnerability where its REST API endpoints do not enforce visibility or moderation restrictions. This allows unauthenticated attackers to access private, unlisted, or pending directory entries, exposing sensitive data like names, organizations, biographies, internal notes, and addresses.

Detection Guidance

Check if the Connections Business Directory plugin version 10.4.67 or below is installed. Test unauthenticated access to REST API endpoints like /cn-api/v1/ to see if private or unlisted entries are exposed. Use tools like curl to query these endpoints directly.

Impact Analysis

This vulnerability allows attackers to retrieve sensitive directory information without authentication. If you use this plugin, private or restricted entries may be exposed, leading to potential privacy breaches, data leaks, or misuse of personal information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing personal data without authorization. Organizations may face legal penalties, fines, or reputational damage due to unauthorized data disclosure.

Mitigation Strategies

Remove the Connections Business Directory plugin immediately as no fixed version is available. If removal is not possible, restrict unauthenticated access to its REST API routes through server configurations or firewall rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86789. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart