Connections Business Directory < 9.7 - Admin+ CSV Injection
No sign of exploitation. No public exploitation artifact known so far.
The Connections Business Directory WordPress plugin before version 9.7 fails to properly validate or clean user input in certain fields, allowing attackers with admin or higher privileges to inject malicious code into CSV exports that could execute when opened in spreadsheet applications.
CSV injection vulnerability in Connections Business Directory < 9.7 where insufficient input validation on specific connection fields permits authenticated admin+ users to craft payloads that execute formulas when exported CSV files are processed by spreadsheet applications like Excel or LibreOffice. Attack requires admin or elevated privileges to inject malicious content into connection records.