plugin

Simple File List Vulnerabilities

44 known security issues reported for the Simple File List WordPress plugin. Most recent disclosed Aug 21, 2026.

2 critical 7 high 12 medium

Running Simple File List on your site? Check whether your installed version is affected.

Scan your site free

Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read

high

The Simple File List plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.3.11. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to read arbitrary files on the server, including sensitive configuration files...

CVSS:
7.5
Affected:
up to 6.3.11
Fix:
No patched version reported
Disclosed:
Aug 21, 2026

CVE-2026-16616 on NVD →

Simple File List <= 6.3.11 - Unauthenticated Stored Cross-Site Scripting

high

The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.3.11. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve...

CVSS:
7.2
Affected:
up to 6.3.11
Fix:
No patched version reported
Disclosed:
Aug 21, 2026

CVE-2026-16617 on NVD →

Simple File List <= 6.3.8 - Reflected Cross-Site Scripting

medium

The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 6.3.8
Fixed in:
6.3.9
Disclosed:
Jul 7, 2026

CVE-2026-57382 on NVD →

Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute

medium

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform arbit...

CVSS:
6.5
Affected:
up to 6.3.7
Fixed in:
6.3.8
Disclosed:
Jun 19, 2026

CVE-2026-12119 on NVD →

Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter

high

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to...

CVSS:
7.5
Affected:
up to 6.3.7
Fixed in:
6.3.8
Disclosed:
Jun 19, 2026

CVE-2026-11911 on NVD →

Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action

high

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the admin...

CVSS:
7.5
Affected:
up to 6.3.7
Fixed in:
6.3.8
Disclosed:
Jun 19, 2026

CVE-2026-11912 on NVD →

Simple File List [simple-file-list] <= 6.1.15 (unfixed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Path Traversal.This issue affects Simple File List: from n/a through <= 6.1.15.

Affected:
up to 6.1.15
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-24953 on NVD →

Simple File List <= 6.1.15 - Authenticated (Subscriber+) Arbitrary File Download

medium

The Simple File List plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
6.5
Affected:
up to 6.1.15
Fixed in:
6.1.16
Disclosed:
Feb 9, 2026

CVE-2026-24953 on NVD →

Simple File List <= 6.3.7 - Missing Authorization

medium

The Simple File List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 6.3.7
Fixed in:
6.3.8
Disclosed:
Dec 25, 2025

CVE-2025-68591 on NVD →

Simple File List [simple-file-list] <= 6.1.15 (unfixed)

unknown

[en] Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.15.

Affected:
up to 6.1.15
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68591 on NVD →

Simple File List [simple-file-list] < 6.1.15

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List allows Path Traversal. This issue affects Simple File List: from n/a through 6.1.14.

Affected:
up to 6.1.15
Fixed in:
6.1.15
Disclosed:
Aug 20, 2025

CVE-2025-54021 on NVD →

Simple File List <= 6.1.14 - Unauthenticated Arbitrary File Download

medium

The Simple File List plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.14. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
5.3
Affected:
up to 6.1.14
Fixed in:
6.1.15
Disclosed:
Jul 28, 2025

CVE-2025-54021 on NVD →

Simple File List [simple-file-list] < 4.2.3

unknown

[en] The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Jul 12, 2025

CVE-2020-36847 on NVD →

Simple File List [simple-file-list] < 4.2.3

unknown
Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Jul 9, 2025

CVE-2025-34085 on NVD →

Simple File List <= 6.1.13 - Missing Authorization to Unauthenticated Minor Settings Update

medium

The Simple File List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eeSFL_BASE_Setup() function in all versions up to, and including, 6.1.13. This makes it possible for unauthenticated attackers to set the eeSFL_Lang option to en_US

CVSS:
5.3
Affected:
up to 6.1.13
Fixed in:
6.1.14
Disclosed:
May 7, 2025

CVE-2025-47450 on NVD →

Simple File List [simple-file-list] < 6.1.14

unknown

[en] Missing Authorization vulnerability in Mitchell Bennis Simple File List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple File List: from n/a through 6.1.13.

Affected:
up to 6.1.14
Fixed in:
6.1.14
Disclosed:
May 7, 2025

CVE-2025-47450 on NVD →

Simple File List [simple-file-list] < 6.1.13

unknown

[en] The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.

Affected:
up to 6.1.13
Fixed in:
6.1.13
Disclosed:
Nov 14, 2024

CVE-2024-10146 on NVD →

Simple File List <= 6.1.11 - Reflected Cross-Site Scripting

medium

The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 6.1.12
Fixed in:
6.1.13
Disclosed:
Oct 24, 2024

CVE-2024-10146 on NVD →

Simple File List [simple-file-list] < 6.1.10

unknown

[en] Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.

Affected:
up to 6.1.10
Fixed in:
6.1.10
Disclosed:
Apr 17, 2024

CVE-2023-44227 on NVD →

Simple File List [simple-file-list] < 6.1.10

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mitchell Bennis Simple File List plugin <= 6.1.9 versions.

Affected:
up to 6.1.10
Fixed in:
6.1.10
Disclosed:
Oct 24, 2023

CVE-2023-39924 on NVD →

Simple File List <= 6.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

medium

The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web s...

CVSS:
4.4
Affected:
up to 6.1.9
Fixed in:
6.1.10
Disclosed:
Oct 12, 2023

CVE-2023-39924 on NVD →

Simple File List <= 6.1.9 - Unauthenticated Arbitrary File Deletion

critical

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 6.1.9. This is due to insufficient controls on files passed to a deletion function. This makes it possible for unauthenticated attackers to delete arbitrary files, which can lead to a denial of service o...

CVSS:
9.1
Affected:
up to 6.1.9
Fixed in:
6.1.10
Disclosed:
Sep 28, 2023

CVE-2023-44227 on NVD →

Simple File List [simple-file-list] < 6.0.10

unknown

[en] The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Mar 27, 2023

CVE-2023-1025 on NVD →

Simple File List <= 6.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...

CVSS:
4.4
Affected:
up to 6.0.9
Fixed in:
6.0.10
Disclosed:
Feb 28, 2023

CVE-2023-1025 on NVD →

Simple File List [simple-file-list] < 4.4.13

unknown

[en] The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.

Affected:
up to 4.4.13
Fixed in:
4.4.13
Disclosed:
Oct 10, 2022

CVE-2022-3208 on NVD →

Simple File List [simple-file-list] < 4.4.12

unknown

[en] The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 4.4.12
Fixed in:
4.4.12
Disclosed:
Oct 10, 2022

CVE-2022-3207 on NVD →

Simple File List [simple-file-list] < 4.4.12

unknown

[en] The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 4.4.12
Fixed in:
4.4.12
Disclosed:
Sep 26, 2022

CVE-2022-3062 on NVD →

Simple File List <= 4.4.12 - Cross-Site Request Forgery to Page Creation

high

The Simple File List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.12. This is due to missing or incorrect nonce validation on its page creation function eeSFL_FREE_CreatePostwithShortcode(). This makes it possible for unauthenticated attackers to create new page...

CVSS:
8.8
Affected:
up to 4.4.12
Fixed in:
4.4.13
Disclosed:
Sep 19, 2022

CVE-2022-3208 on NVD →

Simple File List <= 4.4.11 - Reflected Cross-Site Scripting

medium

The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' and 'subtab' parameters in versions up to, and including, 4.4.11 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.4.11
Fixed in:
4.4.12
Disclosed:
Sep 19, 2022

CVE-2022-3207 on NVD →

Simple File List <= 4.4.11 - Reflected Cross-Site Scripting

medium

The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ and 'subtab' parameters in versions up to, and including, 4.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
6.1
Affected:
up to 4.4.11
Fixed in:
4.4.12
Disclosed:
Aug 26, 2022

CVE-2022-3062 on NVD →

Simple File List [simple-file-list] < 3.2.8

unknown

[en] The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and inc...

Affected:
up to 3.2.8
Fixed in:
3.2.8
Disclosed:
Apr 19, 2022

CVE-2022-1119 on NVD →

Simple File List < 4.2.3 - Remote Code Execution

critical

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Nov 2, 2020

CVE-2020-36847 on NVD →

Simple File List [simple-file-list] < 4.2.3

unknown

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Nov 2, 2020

Simple File List <= 4.2.7 - Arbitrary File Deletion

medium

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CVSS:
6.5
Affected:
up to 4.2.7
Fixed in:
4.2.8
Disclosed:
May 16, 2020

CVE-2020-12832 on NVD →

Simple File List [simple-file-list] < 4.2.8

unknown

[en] WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

Affected:
up to 4.2.8
Fixed in:
4.2.8
Disclosed:
May 13, 2020

CVE-2020-12832 on NVD →

Simple File List [simple-file-list] < 4.2.3

unknown

Unauthenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) discovered by h00die and coiffeur in WordPress Simple File List plugin (versions <= 4.2.2).

Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Apr 27, 2020

Simple File List [simple-file-list] < 3.2.5

unknown

Unauthenticated Arbitrary File Download vulnerability found by Admavidhya N in WordPress Simple File List plugin (versions <= 3.2.4).

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
May 27, 2019

Simple File List [simple-file-list] < 3.2.5

unknown

Authenticated Arbitrary File Delete vulnerability found by Admavidhya N in WordPress Simple File List plugin (versions <= 3.2.4).

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
May 27, 2019

Simple File List <= 3.2.4 - Arbitrary File Deletion

high

The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2.4. This is due to the upward path traversal via the 'eeDeleteFile' parameter. This makes it possible for unauthenticated attackers to delete files within the vulnerable service.

CVSS:
8.6
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
May 23, 2019

Simple File List <= 3.2.7 - Arbitrary File Download

high

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and includin...

CVSS:
7.5
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
May 23, 2019

CVE-2022-1119 on NVD →

Simple File List [simple-file-list] < 3.2.5

unknown

The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2.4. This is due to the upward path traversal via the 'eeDeleteFile' parameter. This makes it possible for unauthenticated attackers to delete files within the vulnerable service.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
May 23, 2019

Simple File List [simple-file-list] < 3.2.8

unknown

This vulnerability allows any user to download sensitive information by traversing the path Authentication required: NO

Affected:
up to 3.2.8
Fixed in:
3.2.8

Simple File List [simple-file-list] < 3.2.5

unknown

Arbitrary File Delete exist in Simple File List Plugin v 3.2.4 or below Authentication Required: Yes

Affected:
up to 3.2.5
Fixed in:
3.2.5

Simple File List [simple-file-list] < 4.2.3

unknown

The Simple File List WordPress plugin was found to be vulnerable to an unauthenticated arbitrary file upload leading to remote code execution. The Python exploit first uploads a file containing PHP code but with a png image file extension. A second request is sent to move (rename) the png file to a php file.

Affected:
up to 4.2.3
Fixed in:
4.2.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database