Junglewise Threat Intelligence

CVE-2026-57682: QuantumCloud Simple Link Directory unauthenticated XSS

CVE-2026-57682 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: QuantumCloud Simple Link Directory. Vendors: QuantumCloud.

Executive brief

Simple Link Directory is a WordPress plugin used to create and manage link directories on websites. A security flaw allows unauthenticated attackers to inject malicious scripts into the site, which could lead to unauthorized redirects, advertisement injection, or the theft of user session information when a victim visits a compromised page. This vulnerability can be exploited without a password, though it typically requires a user to click a link or visit a specific page.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the QuantumCloud Simple Link Directory plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim to interact with a specially crafted link or page (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized redirection, or defacement of the site as viewed by the victim. The vulnerability is addressed in version 15.0.6.

Affected products

  • QuantumCloud Simple Link Directory <= 15.0.5

Timeline

  • 2026-05-02: other: Reported by researcher dutafi
  • 2026-06-30: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: NVD publication date
  • 2026-06-30: patched: Version 15.0.6 released

References

Related threats