Executive brief
Simple Link Directory Pro is a WordPress plugin used to create and manage link directories. A security flaw allows unauthenticated attackers to force the website to make requests to internal or external servers. This could lead to the exposure of sensitive information from other services running on the same network or be used to bypass security controls.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Simple Link Directory Pro plugin for WordPress due to insufficient validation of user-supplied URLs. An unauthenticated remote attacker can exploit this by sending crafted requests that cause the server to initiate network connections to arbitrary domains or internal IP addresses. This can be used to scan internal networks, access metadata services, or interact with other internal services that are not intended to be public. The vulnerability is addressed in version 15.0.7.
Affected products
- QuantumCloud Simple Link Directory Pro <= 15.0.6
Timeline
- 2026-06-10: disclosed: Reported by researcher luc
- 2026-07-27: advisory: Published by Patchstack and NVD
- 2026-07-27: patched: Version 15.0.7 released to address the issue