CVE-2025-49901: WordPress Simple Link Directory plugin < 14.8.1 - Broken Authentication vulnerability
Published Oct 22, 2025
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.
Affected Software
2 affected components
QuantumCloud Simple Link Directory<14.8.1
WordPress Simple Link Directory plugin<14.8.1
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49901?
CVE-2025-49901 has been classified as a medium severity vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2025-49901?
To fix CVE-2025-49901, you should upgrade Simple Link Directory to version 14.8.1 or later.
3
What systems are affected by CVE-2025-49901?
CVE-2025-49901 affects versions of the Simple Link Directory prior to 14.8.1.
4
What type of vulnerability is CVE-2025-49901?
CVE-2025-49901 is an authentication bypass vulnerability that allows unauthorized access through an alternate path.
5
Can the WordPress Simple Link Directory plugin be vulnerable to CVE-2025-49901?
Yes, the WordPress Simple Link Directory plugin is also affected by CVE-2025-49901 if running versions prior to 14.8.1.