Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes
CVE-2026-53742
5.1MEDIUM
What is CVE-2026-53742?
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
Affected Version(s)
Simple Link Directory 0 <= 9.0.4
