Description
Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Published: 2025-05-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control in the quantumcloud Simple Link Directory WordPress plugin, allowing unauthorized users to perform actions normally restricted – this capability is inferred from the description because the notice does not explicitly list the specific actions. The weakness is classified as CWE‑862, indicating a failure to enforce appropriate privileges on users, leading to potential integrity and confidentiality risks for site content managed by the plugin.

Affected Systems

All releases of the Simple Link Directory plugin older than 14.8.1 run on WordPress sites are affected. The plugin is a WordPress extension that manages external links, so any site that has not upgraded to the fixed version is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests the probability of a public exploit is currently low. The issue is not listed in the CISA KEV catalog. Attackers could exploit the flaw by sending crafted HTTP requests to the plugin’s endpoints—this method is inferred because the description does not detail the exploitation steps—taking advantage of the misconfigured access controls to gain unauthorized privileges and manipulate link data. The risk remains moderate, but failure to remediate could enable site owners to lose control over linked resources.

Generated by OpenCVE AI on May 1, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Simple Link Directory plugin to version 14.8.1 or later.
  • If an update is not feasible, consider disabling or removing the plugin to prevent exploitation.
  • Restrict access to the plugin’s administrative URLs by adding .htaccess rules or configuring role‑based permissions so that only authorized administrators can reach them.

Generated by OpenCVE AI on May 1, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15483 Missing Authorization vulnerability in quantumcloud Simple Link Directory Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Link Directory Pro: from n/a through 14.7.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in quantumcloud Simple Link Directory Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Link Directory Pro: from n/a through 14.7.3. Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Title WordPress Simple Link Directory Pro plugin <= 14.7.3 - Broken Access Control Vulnerability WordPress Simple Link Directory Pro plugin < 14.8.1 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 16 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 16:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in quantumcloud Simple Link Directory Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Link Directory Pro: from n/a through 14.7.3.
Title WordPress Simple Link Directory Pro plugin <= 14.7.3 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:21.332Z

Reserved: 2025-04-04T10:02:46.815Z

Link: CVE-2025-32296

cve-icon Vulnrichment

Updated: 2025-05-16T16:37:16.165Z

cve-icon NVD

Status : Deferred

Published: 2025-05-16T16:15:39.243

Modified: 2026-04-23T15:28:55.323

Link: CVE-2025-32296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:45:06Z

Weaknesses