Authentication Bypass Using an Alternate Path or Channel in the quantumcloud Simple Link Directory (qc-simple-link-directory) plugin allows attackers to bypass intended authentication checks via an alternate path/channel, resulting in authentication abuse. Affects versions through < 14.8.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script, CVE-2025-49901.py, plus a README and license. The exploit targets CVE-2025-49901 in the WordPress quantumcloud Simple Link Directory plugin before 14.8.1. Its purpose is to automate unauthenticated abuse of the plugin's qc-opd password reset flow: it probes likely SLD/reset-related pages, extracts a WordPress nonce, enumerates candidate usernames, submits password reset requests that set accounts to a fixed password (newhackerpass123), and then verifies successful access using both session-cookie checks and direct login/admin panel probes. The script is interactive, supports concurrent scanning with ThreadPoolExecutor, throttling delays, and writes strictly verified successful compromises to scan_results/reset_mass_success.txt. Based on the README and visible code, the exploit is not just a detector; it performs full account takeover by resetting credentials and validating access. The repository is small and focused, with one operational Python entry point and documentation describing the attack flow, setup, and expected output.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.