VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67465

CVE-2025-67465

Description

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross Site Request Forgery.This issue affects Simple Link Directory: from n/a through <= 8.8.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Simple Link Directory plugin ≤8.8.3 has a CSRF flaw allowing attackers to force privileged users into unwanted actions.

Vulnerability

Overview

The Simple Link Directory plugin for WordPress, versions up to and including 8.8.3, contains a Cross-Site Request Forgery (CSRF) vulnerability [1]. This flaw arises from insufficient validation of request origins, enabling an attacker to craft malicious requests that appear legitimate to the server.

Exploitation

Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked must be tricked into clicking a crafted link, visiting a malicious page, or submitting a specially designed form while authenticated to the WordPress site [1]. No additional privileges are needed beyond the victim's existing session.

Impact

Successful CSRF attacks can force the victim to perform unintended actions under their current authentication, such as changing plugin settings, adding or deleting links, or other administrative operations [1]. This could lead to unauthorized configuration changes or data manipulation.

Mitigation

The vulnerability is patched in version 8.8.8.8.4 [1]. Users are strongly advised to update immediately. For those unable to update, consulting a hosting provider or web developer is recommended [1]. The issue is rated as low severity (CVSS 4.3) and is considered unlikely to be exploited in mass campaigns, though prompt patching is still advised.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.