CVE-2026-53741: Simple Link Directory Stored XSS via sld_no_results_found Option
Simple Link Directory versions up to 9.0.4 contain a stored cross-site scripting (XSS) vulnerability in the 'sld_no_results_found' option. An authenticated user can inject malicious JavaScript that persists in the application's configuration. When the plugin renders this option on the frontend, the payload breaks out of its intended string context and executes in the browser of every visitor, potentially compromising site visitors' sessions, stealing credentials, or spreading malware.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.4 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-10 / 2026-06-17
NVD description (verbatim)
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from improper output encoding when the plugin interpolates the sld_no_results_found setting into JavaScript code. Although the application calls sanitize_text_field() on input, this WordPress function does not remove or encode quote characters—it only strips tags. An attacker with authenticated access can craft a payload containing quotes to break out of the JavaScript string literal and inject arbitrary code. This code executes in the DOM context of each page load, making it a classic stored XSS with a broad attack surface across all site visitors.
Business impact
This vulnerability enables account takeover, session hijacking, and defacement at scale. Because the malicious script runs for every visitor without re-authentication, attackers can harvest admin credentials, inject phishing redirects, or inject drive-by downloads. For multi-user WordPress sites and public directories, the blast radius extends beyond the WordPress admin panel to all frontend visitors. The stored nature means the attack persists until remediation, increasing dwell time and exposure window.
Affected systems
Simple Link Directory plugin versions through 9.0.4 are vulnerable. The vulnerability requires authenticated access to modify the sld_no_results_found plugin option, typically available to users with sufficient permissions (likely administrator or editor roles). Any WordPress installation using this plugin with user roles capable of modifying plugin settings is at risk.
Exploitability
Exploitation requires valid WordPress user credentials (PR:L in CVSS terms) and user interaction in the form of visiting a page where the malicious option is rendered (UI:R). The technical barrier to crafting a payload is low—breaking out of a JavaScript string literal is straightforward. However, the prerequisite authentication step limits the immediate threat surface compared to unauthenticated XSS. The CVSS score of 5.4 (MEDIUM) reflects this constraint, though the actual business impact can be significant depending on the site's user privileges and visitor volume.
Remediation
Immediate mitigation requires updating Simple Link Directory to a patched version beyond 9.0.4 (verify the exact patched version against the vendor's official advisory). Until patching is possible, administrators should review access controls and restrict the 'manage plugin settings' capability to trusted administrators only. Consider using a Web Application Firewall (WAF) rule to block requests containing common XSS payloads in plugin option submissions, though this is not a substitute for patching.
Patch guidance
Contact the Simple Link Directory developers or check their official repository for an available patch version addressing CVE-2026-53741. Apply the update to all WordPress installations running version 9.0.4 or earlier as soon as the patch is released. Test the patched version in a staging environment first, especially if you have customizations. Monitor your WordPress admin audit logs for any suspicious option modifications during the window before patching.
Detection guidance
Search WordPress option tables (particularly wp_options) for the sld_no_results_found setting and visually inspect its value for encoded script tags, event handlers, or quote-escape sequences ('"<script>). Use WordPress security plugins with JavaScript injection detection to flag stored XSS payloads. Monitor HTTP request logs for POST requests to wp-admin with the plugin's option parameter and payloads containing JavaScript syntax. Inspect browser console errors and network requests on your public pages for unexpected third-party script inclusions after the plugin renders.
Why prioritize this
Although the CVSS score is MEDIUM (5.4), this vulnerability warrants prompt patching because it affects a public-facing plugin option with cross-site impact. Any authenticated user with settings access becomes a pivot point for site-wide compromise. The stored nature eliminates the need for social engineering or per-victim exploitation—once injected, the payload affects all visitors automatically. Organizations running multi-author or multi-user WordPress sites should prioritize this update. However, since it requires authentication and does not appear on the CISA KEV catalog, it is not an immediate critical emergency compared to unauthenticated critical flaws.
Risk score, explained
The CVSS 3.1 score of 5.4 reflects a network-accessible vulnerability (AV:N) with low attack complexity (AC:L), but requiring login (PR:L) and user interaction to trigger (UI:R). The scope is changed (S:C) because the impact crosses trust boundaries—affecting other users' browsers. Confidentiality and integrity are impacted (C:L, I:L) through session theft or page content injection, but availability is not affected (A:N). The MEDIUM rating appropriately captures a vulnerability that is easily exploitable by insiders but does not threaten system availability and requires authentication.
Frequently asked questions
Can an unauthenticated attacker exploit this vulnerability?
No. The vulnerability requires valid WordPress credentials and the ability to modify the sld_no_results_found option, which is typically restricted to administrator or editor roles. However, any compromised or malicious user account with these permissions becomes a risk vector.
How long has this vulnerability been exploitable in the wild?
The vulnerability was published on 2026-06-10. We have no evidence of widespread exploitation or active use in the wild. Monitor your site's admin logs for suspicious option changes during the period before you patch.
What is the difference between this vulnerability and other plugin XSS issues?
This is a stored (persistent) XSS triggered by an authenticated user modifying settings, not a reflected XSS requiring victim social engineering. The payload executes for all visitors automatically, making remediation urgent once a malicious actor gains access.
If I restrict admin access, am I protected?
Restricting admin capabilities reduces risk significantly by limiting who can inject the payload. However, this is not a substitute for patching. You should both apply the update and follow the principle of least privilege for user roles.
This analysis is based on publicly disclosed information as of 2026-06-17. The vulnerability details, CVSS score, and affected versions are derived from official CVE records and vendor disclosures. No exploit code or weaponized proof-of-concept is provided. Organizations should verify patch availability with the Simple Link Directory vendor before deploying updates. This assessment does not constitute professional security advice; consult your security team or a qualified professional for guidance specific to your environment. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide