Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Published: 2025-10-22
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication bypass that allows attackers to gain privileged access by using an alternate path or channel within the WordPress Simple Link Directory plugin. The flaw enables authentication abuse, effectively letting an attacker perform any actions granted to an authenticated user. Because of its severe impact, a successful exploitation could result in full site compromise, leakage of sensitive data, and potential deployment of malware. The weakness is an authentication assurance failure, identified as CWE-288.

Affected Systems

Affected systems are WordPress sites that use the quantumcloud Simple Link Directory plugin with a version older than 14.8.1, including all releases up to 14.8.0. Any site that has not applied the 14.8.1 update or later remains vulnerable. No specific operating system or server version restrictions are noted, so the vulnerability persists as long as the older plugin is installed.

Risk and Exploitability

With a CVSS score of 9.8, the vulnerability is classified as critical. The EPSS score of less than 1% indicates a very low current exploitation probability, but the flaw remains exploitable and is not listed in CISA KEV. The CVE indicates that authentication abuse can be achieved via an alternate path or channel within the plugin, allowing attackers to gain privileged access. The specific attack vector, required configuration, or exploitation steps are not detailed in the CVE data, so any further speculation about exploitation methods is inferred but not confirmed. This potential bypass could expose vulnerable installations to unauthorized actions if the plugin is left unpatched.

Generated by OpenCVE AI on April 29, 2026 at 23:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Simple Link Directory plugin to version 14.8.1 or later to apply the authentication patch.
  • If an immediate update is not possible, isolate the plugin by blocking or disabling all endpoints that are not essential and enforce strict access controls on the WordPress admin area.
  • Implement monitoring for unauthenticated requests to the plugin’s alternate paths and review logs for suspicious activity.

Generated by OpenCVE AI on April 29, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud simple Link Directory
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud simple Link Directory
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Title WordPress Simple Link Directory plugin < 14.8.1 - Broken Authentication vulnerability
Weaknesses CWE-288
References

Subscriptions

Quantumcloud Simple Link Directory
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:23:39.925Z

Reserved: 2025-06-11T16:06:34.447Z

Link: CVE-2025-49901

cve-icon Vulnrichment

Updated: 2025-10-22T20:28:17.333Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:36.243

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-49901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T00:00:14Z

Weaknesses