Description
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross‑Site Scripting (XSS) has been identified in the WordPress Simple Link Directory plugin up to version 15.0.5. The flaw permits an attacker to inject malicious JavaScript into webpages served by a vulnerable site. Potential implications such as cookie theft, session hijacking, or alteration of page content are inferred from typical XSS behavior but are not explicitly detailed in the CVE description. Because the vulnerability does not require authentication, any user visiting a compromised page could be affected.

Affected Systems

The affected product is the QuantumCloud Simple Link Directory WordPress plugin, version 15.0.5 and earlier. WordPress installations that have not upgraded beyond 15.0.5 are susceptible to the XSS flaw.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score of <1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. The likely attack vector is inferred to be an unauthenticated web request that submits a crafted link entry containing malicious payload, based on the plugin’s link submission feature, though the CVE description does not explicitly describe how the attack is carried out. Any publicly accessible site with the affected plugin could be a target.

Generated by OpenCVE AI on July 21, 2026 at 11:39 UTC.

Remediation

Vendor Solution

Update the WordPress Simple Link Directory Plugin to the latest available version (at least 15.0.6).


OpenCVE Recommended Actions

  • Update the WordPress Simple Link Directory plugin to version 15.0.6 or later.
  • If an immediate upgrade is not possible, restrict the link submission capability to administrators only or disable it until the fix is applied.
  • Implement a strict Content Security Policy that disallows inline scripts, reducing risk if exploitation occurs.

Generated by OpenCVE AI on July 21, 2026 at 11:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud simple Link Directory
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud simple Link Directory
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
Title WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Quantumcloud Simple Link Directory
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:45:25.905Z

Reserved: 2026-06-25T08:03:42.567Z

Link: CVE-2026-57682

cve-icon Vulnrichment

Updated: 2026-07-02T19:45:19.253Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')