CVE-2025-48297: WordPress Simple Link Directory < 14.8.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48297?
CVE-2025-48297 has a moderate severity level, indicating a potential risk for web applications due to reflected XSS.
How do I fix CVE-2025-48297?
To fix CVE-2025-48297, update the Simple Link Directory plugin for WordPress to the latest version beyond 14.8.1.
What types of attacks can CVE-2025-48297 allow?
CVE-2025-48297 can allow attackers to execute reflected Cross-site Scripting (XSS) attacks, potentially compromising user data.
Which versions of Simple Link Directory are affected by CVE-2025-48297?
CVE-2025-48297 affects all versions of Simple Link Directory up to but not including version 14.8.1.
Who is impacted by CVE-2025-48297?
Any website using the Simple Link Directory plugin version 14.8.1 or earlier is vulnerable to CVE-2025-48297.