Junglewise Threat Intelligence

CVE-2026-61981: QuantumCloud Simple Link Directory Pro CSRF

CVE-2026-61981 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Vendors: QuantumCloud.

Executive brief

Simple Link Directory Pro, a WordPress plugin used for creating and managing link directories, is vulnerable to a security flaw that could allow an attacker to perform unauthorized actions. By tricking a logged-in administrator into clicking a malicious link or visiting a compromised website, an attacker can change settings or delete content without the administrator's knowledge. This could lead to unauthorized modifications of the directory or a disruption of the service.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Simple Link Directory Pro plugin for WordPress due to missing nonce validation on sensitive administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a site administrator into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform unauthorized state-changing actions, such as modifying directory settings or deleting entries, impacting the integrity and availability of the plugin's data. The issue is addressed in version 15.0.9.

Affected products

  • QuantumCloud Simple Link Directory Pro <= 15.0.8

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats