Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read
high
The Simple File List plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.3.11. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to read arbitrary files on the server, including sensitive configuration files...
- CVSS:
- 7.5
- Affected:
- up to 6.3.11
- Fix:
- No patched version reported
- Disclosed:
- Aug 21, 2026
CVE-2026-16616 on NVD →
Simple File List <= 6.3.11 - Unauthenticated Stored Cross-Site Scripting
high
The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.3.11. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve...
- CVSS:
- 7.2
- Affected:
- up to 6.3.11
- Fix:
- No patched version reported
- Disclosed:
- Aug 21, 2026
CVE-2026-16617 on NVD →
Simple File List <= 6.3.8 - Reflected Cross-Site Scripting
medium
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 6.3.8
- Fixed in:
- 6.3.9
- Disclosed:
- Jul 7, 2026
CVE-2026-57382 on NVD →
Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
medium
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform arbit...
- CVSS:
- 6.5
- Affected:
- up to 6.3.7
- Fixed in:
- 6.3.8
- Disclosed:
- Jun 19, 2026
CVE-2026-12119 on NVD →
Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
high
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to...
- CVSS:
- 7.5
- Affected:
- up to 6.3.7
- Fixed in:
- 6.3.8
- Disclosed:
- Jun 19, 2026
CVE-2026-11911 on NVD →
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
high
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the admin...
- CVSS:
- 7.5
- Affected:
- up to 6.3.7
- Fixed in:
- 6.3.8
- Disclosed:
- Jun 19, 2026
CVE-2026-11912 on NVD →
Simple File List [simple-file-list] <= 6.1.15 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Path Traversal.This issue affects Simple File List: from n/a through <= 6.1.15.
- Affected:
- up to 6.1.15
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2026-24953 on NVD →
Simple File List <= 6.1.15 - Authenticated (Subscriber+) Arbitrary File Download
medium
The Simple File List plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 6.5
- Affected:
- up to 6.1.15
- Fixed in:
- 6.1.16
- Disclosed:
- Feb 9, 2026
CVE-2026-24953 on NVD →
Simple File List <= 6.3.7 - Missing Authorization
medium
The Simple File List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 6.3.7
- Fixed in:
- 6.3.8
- Disclosed:
- Dec 25, 2025
CVE-2025-68591 on NVD →
Simple File List [simple-file-list] <= 6.1.15 (unfixed)
unknown
[en] Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.15.
- Affected:
- up to 6.1.15
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68591 on NVD →
Simple File List [simple-file-list] < 6.1.15
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List allows Path Traversal. This issue affects Simple File List: from n/a through 6.1.14.
- Affected:
- up to 6.1.15
- Fixed in:
- 6.1.15
- Disclosed:
- Aug 20, 2025
CVE-2025-54021 on NVD →
Simple File List <= 6.1.14 - Unauthenticated Arbitrary File Download
medium
The Simple File List plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.14. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 6.1.14
- Fixed in:
- 6.1.15
- Disclosed:
- Jul 28, 2025
CVE-2025-54021 on NVD →
Simple File List [simple-file-list] < 4.2.3
unknown
[en] The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Jul 12, 2025
CVE-2020-36847 on NVD →
Simple File List [simple-file-list] < 4.2.3
unknown
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Jul 9, 2025
CVE-2025-34085 on NVD →
Simple File List <= 6.1.13 - Missing Authorization to Unauthenticated Minor Settings Update
medium
The Simple File List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eeSFL_BASE_Setup() function in all versions up to, and including, 6.1.13. This makes it possible for unauthenticated attackers to set the eeSFL_Lang option to en_US
- CVSS:
- 5.3
- Affected:
- up to 6.1.13
- Fixed in:
- 6.1.14
- Disclosed:
- May 7, 2025
CVE-2025-47450 on NVD →
Simple File List [simple-file-list] < 6.1.14
unknown
[en] Missing Authorization vulnerability in Mitchell Bennis Simple File List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple File List: from n/a through 6.1.13.
- Affected:
- up to 6.1.14
- Fixed in:
- 6.1.14
- Disclosed:
- May 7, 2025
CVE-2025-47450 on NVD →
Simple File List [simple-file-list] < 6.1.13
unknown
[en] The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.
- Affected:
- up to 6.1.13
- Fixed in:
- 6.1.13
- Disclosed:
- Nov 14, 2024
CVE-2024-10146 on NVD →
Simple File List <= 6.1.11 - Reflected Cross-Site Scripting
medium
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 6.1.12
- Fixed in:
- 6.1.13
- Disclosed:
- Oct 24, 2024
CVE-2024-10146 on NVD →
Simple File List [simple-file-list] < 6.1.10
unknown
[en] Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.
- Affected:
- up to 6.1.10
- Fixed in:
- 6.1.10
- Disclosed:
- Apr 17, 2024
CVE-2023-44227 on NVD →
Simple File List [simple-file-list] < 6.1.10
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mitchell Bennis Simple File List plugin <= 6.1.9 versions.
- Affected:
- up to 6.1.10
- Fixed in:
- 6.1.10
- Disclosed:
- Oct 24, 2023
CVE-2023-39924 on NVD →
Simple File List <= 6.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web s...
- CVSS:
- 4.4
- Affected:
- up to 6.1.9
- Fixed in:
- 6.1.10
- Disclosed:
- Oct 12, 2023
CVE-2023-39924 on NVD →
Simple File List <= 6.1.9 - Unauthenticated Arbitrary File Deletion
critical
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 6.1.9. This is due to insufficient controls on files passed to a deletion function. This makes it possible for unauthenticated attackers to delete arbitrary files, which can lead to a denial of service o...
- CVSS:
- 9.1
- Affected:
- up to 6.1.9
- Fixed in:
- 6.1.10
- Disclosed:
- Sep 28, 2023
CVE-2023-44227 on NVD →
Simple File List [simple-file-list] < 6.0.10
unknown
[en] The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Mar 27, 2023
CVE-2023-1025 on NVD →
Simple File List <= 6.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...
- CVSS:
- 4.4
- Affected:
- up to 6.0.9
- Fixed in:
- 6.0.10
- Disclosed:
- Feb 28, 2023
CVE-2023-1025 on NVD →
Simple File List [simple-file-list] < 4.4.13
unknown
[en] The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.
- Affected:
- up to 4.4.13
- Fixed in:
- 4.4.13
- Disclosed:
- Oct 10, 2022
CVE-2022-3208 on NVD →
Simple File List [simple-file-list] < 4.4.12
unknown
[en] The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.4.12
- Fixed in:
- 4.4.12
- Disclosed:
- Oct 10, 2022
CVE-2022-3207 on NVD →
Simple File List [simple-file-list] < 4.4.12
unknown
[en] The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 4.4.12
- Fixed in:
- 4.4.12
- Disclosed:
- Sep 26, 2022
CVE-2022-3062 on NVD →
Simple File List <= 4.4.12 - Cross-Site Request Forgery to Page Creation
high
The Simple File List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.12. This is due to missing or incorrect nonce validation on its page creation function eeSFL_FREE_CreatePostwithShortcode(). This makes it possible for unauthenticated attackers to create new page...
- CVSS:
- 8.8
- Affected:
- up to 4.4.12
- Fixed in:
- 4.4.13
- Disclosed:
- Sep 19, 2022
CVE-2022-3208 on NVD →
Simple File List <= 4.4.11 - Reflected Cross-Site Scripting
medium
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' and 'subtab' parameters in versions up to, and including, 4.4.11 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 4.4.11
- Fixed in:
- 4.4.12
- Disclosed:
- Sep 19, 2022
CVE-2022-3207 on NVD →
Simple File List <= 4.4.11 - Reflected Cross-Site Scripting
medium
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ and 'subtab' parameters in versions up to, and including, 4.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 4.4.11
- Fixed in:
- 4.4.12
- Disclosed:
- Aug 26, 2022
CVE-2022-3062 on NVD →
Simple File List [simple-file-list] < 3.2.8
unknown
[en] The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and inc...
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.8
- Disclosed:
- Apr 19, 2022
CVE-2022-1119 on NVD →
Simple File List < 4.2.3 - Remote Code Execution
critical
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 2, 2020
CVE-2020-36847 on NVD →
Simple File List [simple-file-list] < 4.2.3
unknown
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 2, 2020
Simple File List <= 4.2.7 - Arbitrary File Deletion
medium
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.
- CVSS:
- 6.5
- Affected:
- up to 4.2.7
- Fixed in:
- 4.2.8
- Disclosed:
- May 16, 2020
CVE-2020-12832 on NVD →
Simple File List [simple-file-list] < 4.2.8
unknown
[en] WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.8
- Disclosed:
- May 13, 2020
CVE-2020-12832 on NVD →
Simple File List [simple-file-list] < 4.2.3
unknown
Unauthenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) discovered by h00die and coiffeur in WordPress Simple File List plugin (versions <= 4.2.2).
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Apr 27, 2020
Simple File List [simple-file-list] < 3.2.5
unknown
Unauthenticated Arbitrary File Download vulnerability found by Admavidhya N in WordPress Simple File List plugin (versions <= 3.2.4).
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 27, 2019
Simple File List [simple-file-list] < 3.2.5
unknown
Authenticated Arbitrary File Delete vulnerability found by Admavidhya N in WordPress Simple File List plugin (versions <= 3.2.4).
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 27, 2019
Simple File List <= 3.2.4 - Arbitrary File Deletion
high
The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2.4. This is due to the upward path traversal via the 'eeDeleteFile' parameter. This makes it possible for unauthenticated attackers to delete files within the vulnerable service.
- CVSS:
- 8.6
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- May 23, 2019
Simple File List <= 3.2.7 - Arbitrary File Download
high
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and includin...
- CVSS:
- 7.5
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8
- Disclosed:
- May 23, 2019
CVE-2022-1119 on NVD →
Simple File List [simple-file-list] < 3.2.5
unknown
The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2.4. This is due to the upward path traversal via the 'eeDeleteFile' parameter. This makes it possible for unauthenticated attackers to delete files within the vulnerable service.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 23, 2019
Simple File List [simple-file-list] < 3.2.8
unknown
This vulnerability allows any user to download sensitive information by traversing the path
Authentication required: NO
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.8
Simple File List [simple-file-list] < 3.2.5
unknown
Arbitrary File Delete exist in Simple File List Plugin v 3.2.4 or below
Authentication Required: Yes
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
Simple File List [simple-file-list] < 4.2.3
unknown
The Simple File List WordPress plugin was found to be vulnerable to an unauthenticated arbitrary file upload leading to remote code execution. The Python exploit first uploads a file containing PHP code but with a png image file extension. A second request is sent to move (rename) the png file to a php file.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3