---
id: CVE-2026-86789
title: >-
  The Connections Business Directory WordPress plugin through 10.4.67 does not
  apply its visibility and moderation-status restrictions on certain REST API
  read endpoints, allowing unauthenticated attackers to retrieve directory
  entries tha…
summary: >-
  The Connections Business Directory WordPress plugin through 10.4.67 does not
  apply its visibility and moderation-status restrictions on certain REST API
  read endpoints, allowing unauthenticated attackers to retrieve directory
  entries tha…
severity: none
cwe:
  - CWE-200
product: Connections Business Directory
affected:
  - connections_business_directory <= 10.4.67
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:07.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86789'
references:
  - url: 'https://wpscan.com/vulnerability/3514e2f9-4dda-45ae-80c0-c7caafcb7d8a/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.553Z'
---

## Overview

The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.
The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
