The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
https://wpscan.com/vulnerability/dd394b55-c86f-4fa2-aae8-5903ca0b95ec
https://github.com/Connections-Business-Directory/Connections/issues/474