CVE-2019-13463: Quantumcloud Simple Link Directory

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html is not called for the "echo get_the_title()" or "echo $term->name" statement.

Affected products

  • Quantumcloud Simple Link Directory: before 7.3.5 (fixed in 7.3.5)

Published 2020-03-20. Last modified 2026-06-17.