{"id":"CVE-2023-29437","summary":"WordPress Connections Business Directory Plugin \u003c= 10.4.36 is vulnerable to Cross Site Scripting (XSS)","details":"Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin \u003c= 10.4.36 versions.","modified":"2026-07-15T01:48:51.716452662Z","published":"2023-06-26T12:00:29.999Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29437.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"10.4.36"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"Patchstack"},"references":[{"type":"WEB","url":"https://wordpress.org/plugins"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29437.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29437"},{"type":"ADVISORY","url":"https://patchstack.com/database/vulnerability/connections/wordpress-connections-business-directory-plugin-10-4-36-cross-site-scripting-xss-vulnerability?_s_id=cve"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/connections-business-directory/connections","events":[{"introduced":"0"},{"last_affected":"6032c81964170a8283c47d084665f3b234c033f0"}],"database_specific":{"cpe":"cpe:2.3:a:connections-pro:connections_business_directory:*:*:*:*:*:wordpress:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"10.4.36"}],"source":"CPE_RANGE"}}],"versions":["10.4.36","10.4.35","10.4.34","10.4.33","10.4.32","10.4.31","10.4.30","10.4.29","10.4.28","10.4.27","10.4.26","10.4.25","10.4.24","10.4.23","10.4.22","10.4.21","10.4.19","10.4.18","10.4.17","10.4.16","10.4.15","10.4.14","10.4.13","10.4.12","10.4.11","10.4.10","10.4.9","10.4.8","10.4.7","10.4.6","10.4.5","10.4.4","10.4.3","10.4.2","10.4.1","10.4","10.3.2","10.3.1","10.3","10.2","10.1","10.0","9.17","9.16","9.15","9.14","9.13","9.12","9.11","9.10","9.9.1","9.9","9.8.2","9.8.1","9.8","9.7.2","9.7.1","9.7","9.6","9.5.1","9.5","9.4.8","9.4.7","9.4.6","9.4.5","9.4.4","9.4.3","9.4.2","9.4.1","9.4","9.3.2","9.3.1","9.3","9.2","9.1.1","9.1","9.0.2","9.0.1","9.0","8.44.1","8.44","8.43","8.42.1","8.42","8.41.2","8.41.1","8.41","8.40.2","8.40.1","8.40","8.39.1","8.39","8.38.1","8.38","8.37","8.36.1","8.36","8.35","8.34","8.33","8.32","8.31","8.30.1","8.30","8.29","8.28.5","8.28.4","8.28.3","8.28.2","8.28.1","8.28","8.27","8.26","8.25.1","8.25","8.24","8.23","8.22","8.21","8.20","8.19.1","8.19","8.18","8.17","8.16","8.15","8.14","8.13","8.12","8.11","8.10","8.9","8.8","8.7.1","8.7","8.6.12","8.6.11","8.6.10","8.6.9","8.6.8","8.6.7","8.6.6","8.6.5","8.6.4","8.6.3","8.6.2","8.6.1","8.6","8.5.32","8.5.31","8.5.30","8.5.29","8.5.28","8.5.27","8.5.26","8.5.25","8.5.24","8.2.23","8.5.22","8.5.21","8.5.20","8.5.19","8.5.18","8.5.17","8.5.16","8.5.15","8.5.14","8.5.13","8.5.12","8.5.11","8.5.10","8.5.9","8.5.8","8.5.7","8.5.6","8.5.5","8.5.4","8.5.3","8.5.2","8.5.1","8.5","8.4.5","8.4.4","8.4.3","8.4.2","8.4.1","8.4","8.3.3","8.3.2","8.3.1","8.3","8.2.10","8.2.9","8.2.8","8.2.7","8.2.6","8.2.5","8.2.4","8.2.3","8.2.2","8.2.1","8.2","8.1.6","8.1.5","8.1.4","8.1.3","8.1.2","8.1.1","8.1","0.8.14","0.8.13","0.8.12","0.8.11","0.8.10","0.8.9","0.8.8","0.8.7","0.8.6","0.8.5","0.8.4","0.8.3","0.7.9.7","0.7.9.6","0.7.9.5","0.7.9.4","0.7.9.3","0.7.9.2","0.7.9.1","0.7.9","0.7.8.1","0.7.8","0.7.7","0.7.6.6","0.7.6.5","0.7.6.4","0.7.6.3","0.7.6.2","0.7.6.1","0.7.6","0.7.5.1","0.7.5","0.7.4.1","0.7.4","0.7.3.7","0.7.3.6","0.7.3.5","0.7.3.4","0.7.3.3","0.7.3.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29437.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"}]}