Unauthenticated Cross-Site Request Forgery in Simple Link Directory Pro by WordPress
CVE-2026-61981

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-61981?

The Simple Link Directory Pro plugin for WordPress is vulnerable to an unauthenticated Cross Site Request Forgery (CSRF) attack, permitting an attacker to trick users into executing unintended actions. This could result in unauthorized access or manipulation of user data without their consent. Users of affected versions up to 15.0.8 are encouraged to update promptly to mitigate potential security risks.

Affected Version(s)

Simple Link Directory Pro <= 15.0.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

luc | Patchstack Bug Bounty Program
.