quantumcloud Vulnerabilities and Affected Products
Vulnerabilities associated with Simple Link Directory.
Products
Clear product- WPBot – AI ChatBot for Live Support, Lead Generation, AI Services15 vulnerabilities
- Simple Link Directory11 vulnerabilities
- ChatBot8 vulnerabilities
- AI ChatBot5 vulnerabilities
- WPBot Pro Wordpress Chatbot5 vulnerabilities
- Conversational Forms for ChatBot4 vulnerabilities
- Simple Business Directory Pro4 vulnerabilities
- AI Infographic Maker2 vulnerabilities
- infographic_maker2 vulnerabilities
- KBx Pro Ultimate2 vulnerabilities
- SEO Help2 vulnerabilities
- Simple Link Directory Pro2 vulnerabilities
- ChatBot for eCommerce – WoowBot1 vulnerability
- ChatBot with AI1 vulnerability
- Floating Action Buttons1 vulnerability
- Floating Buttons for WooCommerce1 vulnerability
- floating_buttons1 vulnerability
- Highlight1 vulnerability
- iChart – Easy Charts and Graphs1 vulnerability
- Infographic Maker – iList1 vulnerability
- QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to Article1 vulnerability
- simple_link_directory1 vulnerability
- simple_video_directory1 vulnerability
- Slider Hero with Video Background, Animation1 vulnerability
- WoowBot Pro Max1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57682HIGH | WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. CWE-79Jul 2, 2026 | CVSS7.1v3.1 | EPSS0.186% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53742MEDIUM | Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode AttributesSimple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser. CWE-79Jun 10, 2026 | CVSS5.1v4.0 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53741MEDIUM | Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found OptionSimple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor. CWE-79Jun 10, 2026 | CVSS5.1v4.0 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7209MEDIUM | Simple Link Directory <= 8.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesThe Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79May 2, 2026 | CVSS6.4v3.1 | EPSS0.195% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67576MEDIUM | WordPress Simple Link Directory plugin <= 8.8.3 - Broken Access Control vulnerabilityMissing Authorization vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through <= 8.8.3. CWE-862Dec 9, 2025 | CVSS5.3v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67465MEDIUM | WordPress Simple Link Directory plugin <= 8.8.3 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross Site Request Forgery.This issue affects Simple Link Directory: from n/a through <= 8.8.3. CWE-352Dec 9, 2025 | CVSS4.3v3.1 | EPSS0.128% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49901CRITICAL | WordPress Simple Link Directory plugin < 14.8.1 - Broken Authentication vulnerabilityAuthentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1. CWE-288Oct 22, 2025 | CVSS9.8v3.1 | EPSS0.693% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-48297HIGH | WordPress Simple Link Directory < 14.8.1 - Cross Site Scripting (XSS) VulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1. CWE-79Aug 20, 2025 | CVSS7.1v3.1 | EPSS0.229% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32297HIGH | WordPress Simple Link Directory Pro plugin < 14.8.1 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1. CWE-89Jul 4, 2025 | CVSS8.5v3.1 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32296MEDIUM | WordPress Simple Link Directory Pro plugin < 14.8.1 - Broken Access Control VulnerabilityMissing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1. CWE-862May 16, 2025 | CVSS5.3v3.1 | EPSS0.289% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12417MEDIUM | Simple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode ExecutionThe The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. CWE-94Dec 13, 2024 | CVSS6.5v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |