← back
CVE-2026-53742mediumCWE-79

Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.1epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N