Impact
The vulnerability is an unauthenticated Cross Site Request Forgery (CSRF; CWE-352) in versions of the Simple Link Directory Pro plugin up to 15.0.8. Based on the description, it is inferred that an attacker can construct a request that, when executed by a logged‑in administrator or user, causes the plugin to perform actions on behalf of that user without authentication. This could lead to unintended changes to the link directory, such as adding, editing, or deleting entries, and potentially affect the site’s content integrity.
Affected Systems
QuantumCloud’s Simple Link Directory Pro WordPress plugin, versions 15.0.8 and earlier, are affected. The plugin provides a directory interface within WordPress and is utilized by sites that host links or references. Users running these versions are at risk.
Risk and Exploitability
The CVSS score of 5.4 classifies the weakness as moderate. The EPSS score is below 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers can exploit the lack of proper CSRF protection by sending a crafted HTTP request that the plugin accepts and forwarding it through a user's session. Though the likelihood of exploitation is low, the potential for unauthorized actions warrants remedial action.
OpenCVE Enrichment