Stored Cross-Site Scripting Vulnerability in Simple Link Directory Plugin for WordPress
CVE-2026-7209
6.4MEDIUM
What is CVE-2026-7209?
The Simple Link Directory plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability through the qcopd-directory shortcode. This issue arises from inadequate input sanitization and output escaping regarding user-provided attributes like title_font_size. As a result, authenticated attackers with contributor-level access or higher can insert arbitrary web scripts into pages, leading to script execution whenever users access those compromised pages.
Affected Version(s)
Simple Link Directory 0 <= 8.9.2