Impact
Unauthenticated Cross‑Site Scripting (XSS) has been identified in the WordPress Simple Link Directory plugin up to version 15.0.5. The flaw permits an attacker to inject malicious JavaScript into webpages served by a vulnerable site. Potential implications such as cookie theft, session hijacking, or alteration of page content are inferred from typical XSS behavior but are not explicitly detailed in the CVE description. Because the vulnerability does not require authentication, any user visiting a compromised page could be affected.
Affected Systems
The affected product is the QuantumCloud Simple Link Directory WordPress plugin, version 15.0.5 and earlier. WordPress installations that have not upgraded beyond 15.0.5 are susceptible to the XSS flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of <1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. The likely attack vector is inferred to be an unauthenticated web request that submits a crafted link entry containing malicious payload, based on the plugin’s link submission feature, though the CVE description does not explicitly describe how the attack is carried out. Any publicly accessible site with the affected plugin could be a target.
OpenCVE Enrichment