CVE-2025-32297: WordPress Simple Link Directory Pro plugin < 14.8.1 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL Injection. This issue affects Simple Link Directory: from n/a through 14.7.3.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32297?
CVE-2025-32297 is considered a high-severity vulnerability due to its ability to allow SQL injection.
How do I fix CVE-2025-32297?
To fix CVE-2025-32297, update the Simple Link Directory to version 14.7.4 or higher.
What is the impact of CVE-2025-32297?
The impact of CVE-2025-32297 includes unauthorized access to the database and potential data leakage.
Which versions are affected by CVE-2025-32297?
CVE-2025-32297 affects QuantumCloud Simple Link Directory and WordPress Simple Link Directory Pro plugin versions up to and including 14.7.3.
Is there a workaround for CVE-2025-32297?
A temporary workaround for CVE-2025-32297 includes disabling the affected plugin until an update can be applied.