CVE-2025-49901
CRITICALquantumcloud Simple Link Directory <14.8.1 - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-49901. PoCs published by Nxploited.
AI-analyzed exploit summary The repository contains a Python script designed to scan WordPress sites for the presence of the 'qc-opd' plugin and identify potential password reset vulnerabilities. It includes functionality to extract nonces and check for specific page structures but does not contain exploit code for CVE-2025-49901.
Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Exploits (1)
The repository contains a Python script designed to scan WordPress sites for the presence of the 'qc-opd' plugin and identify potential password reset vulnerabilities. It includes functionality to extract nonces and check for specific page structures but does not contain exploit code for CVE-2025-49901.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H