{ "schema_version": "1.4.0", "id": "GHSA-cphj-wfqr-mqxx", "modified": "2022-05-24T17:12:00Z", "published": "2022-05-24T17:12:00Z", "aliases": [ "CVE-2019-13463" ], "details": "An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html is not called for the \"echo get_the_title()\" or \"echo $term->name\" statement.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13463" }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fsimple-link-directory&old=2111131&new_path=%2Fsimple-link-directory&new=2111132&sfp_email=&sfph_mail=" }, { "type": "WEB", "url": "https://wordpress.org/plugins/simple-link-directory/#developers" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-03-20T21:15:00Z" } }