Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor. | |
| Title | Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option | |
| First Time appeared |
Quantumcloud
Quantumcloud simple Link Directory |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:quantumcloud:simple_link_directory:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Quantumcloud
Quantumcloud simple Link Directory |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T20:39:45.823Z
Reserved: 2026-06-10T17:16:10.427Z
Link: CVE-2026-53741
No data.
Status : Received
Published: 2026-06-10T22:17:02.503
Modified: 2026-06-10T22:17:02.503
Link: CVE-2026-53741
No data.
OpenCVE Enrichment
Updated: 2026-06-10T23:00:20Z
Weaknesses