WordPress security by component
Simple File List
Plugin description
Simple File List is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
simple-file-listLatest vulnerability
CVE-2026-57382: Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.3.8.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-57382
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.3.8.
|
6.3.9 |
CVE7.1
NVDPending
|
| Jun 20, 2026 |
CVE-2026-12119
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.3.7.
|
> 6.3.7 |
CVE6.5
NVDPending
|
| Jun 20, 2026 |
CVE-2026-11912
Simple File List: A security weakness
Simple File List is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.3.7.
|
> 6.3.7 |
CVE7.5
NVDPending
|
| Jun 20, 2026 |
CVE-2026-11911
Simple File List: Code execution
Simple File List is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 6.3.7.
|
> 6.3.7 |
CVE7.5
NVDPending
|
| Feb 20, 2026 |
CVE-2026-24953
Simple File List: Filesystem traversal
Simple File List is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68591
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Aug 20, 2025 |
CVE-2025-54021
Simple File List: Filesystem traversal
Simple File List is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jul 12, 2025 |
CVE-2020-36847
Simple-File-List: Code execution
Simple-File-List is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| May 07, 2025 |
CVE-2025-47450
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 14, 2024 |
CVE-2024-10146
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Apr 17, 2024 |
CVE-2023-44227
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Oct 25, 2023 |
CVE-2023-39924
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Mar 27, 2023 |
CVE-2023-1025
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Oct 10, 2022 |
CVE-2022-3208
Simple File List: Cross-site request forgery
Simple File List is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Oct 10, 2022 |
CVE-2022-3207
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Sep 26, 2022 |
CVE-2022-3062
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Apr 19, 2022 |
CVE-2022-1119
Simple File List: A security weakness
Simple File List is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| May 13, 2020 |
CVE-2020-12832
Simple File List: Arbitrary file deletion
Simple File List is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
|
See mitigation notes |
CVE9.8
NVD9.8
|