Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Published: 2025-08-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple Link Directory plugin for WordPress contains an improper neutralization of user input during page rendering that allows a reflected cross‑site scripting vulnerability. An attacker can inject arbitrary JavaScript that is executed in the context of a victim’s browser when the crafted payload is reflected back to them, enabling session hijacking, phishing or content defacement. This weakness is classified as CWE‑79.

Affected Systems

The quantumcloud Simple Link Directory plugin, versions older than 14.8.1, are affected. Any installation that has not upgraded past 14.8.1 is vulnerable and may be exposed when a user receives or visits a malicious URL constructed with unsanitized query parameters or form input.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity assessment. The EPSS score of less than 1% signals a low likelihood of widespread exploitation, but the vulnerability remains a viable target for deliberate attacker campaigns. It is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker crafts a malicious link or form submission that contains JavaScript, which is then returned in the plugin’s response and executed within the victim’s browser. Successful exploitation could compromise the confidentiality and integrity of the victim’s session data.

Generated by OpenCVE AI on April 30, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Simple Link Directory plugin to version 14.8.1 or later to eliminate the reflected XSS flaw.
  • If upgrading is not feasible, replace the plugin with an alternative that performs proper input validation and sanitization.
  • Temporarily disable the Simple Link Directory plugin until a patch or secure replacement is available to prevent the vulnerability from being exploitable.

Generated by OpenCVE AI on April 30, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25371 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud simple Link Directory
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud simple Link Directory
Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a.
Title WordPress Simple Link Directory < 14.8.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Quantumcloud Simple Link Directory
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:55.649Z

Reserved: 2025-05-19T14:13:37.940Z

Link: CVE-2025-48297

cve-icon Vulnrichment

Updated: 2025-08-20T17:43:12.977Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:33.513

Modified: 2026-04-23T15:31:03.363

Link: CVE-2025-48297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:30:06Z

Weaknesses