PT-2026-48556 · WordPress · Simple Link Directory

CVE-2026-53742

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Simple Link Directory versions prior to 9.0.5
Description The software echoes embed shortcode attributes into HTML data attributes without proper escaping in the embedder template. This allows attackers with contributor access to craft a shortcode attribute that injects an event handler, leading to stored Cross-Site Scripting (XSS), where malicious scripts are executed in the browser of a user viewing the content.
Recommendations Update to version 9.0.5 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53742

Affected Products

Simple Link Directory