S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0760 Scanner

CVE-2022-0760 scanner - SQL Injection vulnerability in Simple Link Directory plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0760
9.8
CVSS

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Simple Link Directory
AFFECTED< 7.7.2SAFE ✓≥ 7.7.2
Updated Aug 22, 2026View on NVD →
Detail

The Simple Link Directory plugin is a popular WordPress plugin that allows administrators to create simple and responsive directories for their website. It is a straightforward and easy-to-use plugin that has been downloaded by over 20,000 users worldwide. The plugin is designed to simplify website navigation for users by providing a search and filter system that can categorize links based on various parameters.

However, a severe vulnerability recently surfaced in this plugin, attracting the attention of the cybersecurity community. Tracked as CVE-2022-0760, this vulnerability has been identified as an unauthenticated SQL injection flaw. The Simple Link Directory plugin before version 7.7.2 does not validate and escape the post_id parameter correctly before using it in an SQL statement via the qcopd_upvote_action AJAX action, which is available to both authenticated and unauthenticated users.

An attacker can exploit this vulnerability to take over the targeted WordPress website by injecting malicious SQL code into the search parameter. The attacker can then gain access to sensitive information stored on the website's database, alter the database, or even execute arbitrary code. The vulnerability can be exploited without requiring any authentication, allowing any attacker with access to the search parameters to carry out attacks.

In conclusion, it is essential to take cybersecurity vulnerabilities in WordPress plugins seriously. The Simple Link Directory plugin is just one of the many plugins that can expose a website's database to attackers. With the help of the s4e.io platform, website administrators can easily and quickly learn about vulnerabilities in their digital assets and protect against attacks.

 

REFERENCES

Solution Advice

To protect WordPress websites from the Simple Link Directory plugin vulnerability, administrators can take a few precautions:

  • Upgrade to the latest version of the Simple Link Directory plugin (version 7.7.2 or higher).
  • Restrict access to the qcopd_upvote_action AJAX action.
  • Regularly scan WordPress plugins for vulnerabilities using tools such as the securityforeveryone.com platform.
  • Implement robust security practices such as keeping up-to-date backups, deploying a web application firewall, and employing proper access control mechanisms.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.