CVE-2026-86789 Connections Business Directory 信息泄露漏洞
影响未授权攻击者可读取私密或待审核目录条目信息
Connections Business Directory 是 WordPress 的目录/名录插件。其部分 REST API 读取端点未应用可见性与审核状态限制,导致未认证攻击者可获取本应受保护的目录条目数据。该漏洞影响 10.4.67 及之前版本。
影响范围
Connections Business Directory WordPress 插件 10.4.67 及之前版本;该插件已在 WordPress.org 下架,暂无已修复版本。
漏洞详情
漏洞类型为访问控制缺失导致的信息泄露。插件对某些 REST API 读取接口未校验条目的可见性(private/unlisted)与审核状态(pending),也未要求身份认证。攻击者直接请求这些接口即可获取条目名称、组织、简介、内部备注和街道地址等敏感字段。
利用条件与风险
利用无需认证,攻击者只需能访问目标站点的 REST API 路由即可批量抓取数据,实战中可导致隐私信息与内部备注泄露。CVSS 5.3,风险中等。
修复建议
官方暂无修复版本且插件已下架,建议卸载该插件;如必须保留,应限制对相关 REST API 路由的未认证访问(如通过 WAF 或访问控制规则拦截)。
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.
The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.