← WordPress Vulnerabilities
WordPress security by component

Simple File List

Simple File List is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: simple-file-list

CVE-2026-57382: Simple File List: Cross-site scripting

Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.3.8.

PublishedJul 13, 2026
Known safe version6.3.9
Safe version
Jul 13, 2026 CVE-2026-57382
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.3.8.
6.3.9
CVE7.1
NVDPending
Jun 20, 2026 CVE-2026-12119
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.3.7.
> 6.3.7
CVE6.5
NVDPending
Jun 20, 2026 CVE-2026-11912
Simple File List: A security weakness
Simple File List is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.3.7.
> 6.3.7
CVE7.5
NVDPending
Jun 20, 2026 CVE-2026-11911
Simple File List: Code execution
Simple File List is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 6.3.7.
> 6.3.7
CVE7.5
NVDPending
Feb 20, 2026 CVE-2026-24953
Simple File List: Filesystem traversal
Simple File List is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Dec 24, 2025 CVE-2025-68591
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Aug 20, 2025 CVE-2025-54021
Simple File List: Filesystem traversal
Simple File List is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Jul 12, 2025 CVE-2020-36847
Simple-File-List: Code execution
Simple-File-List is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
May 07, 2025 CVE-2025-47450
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 14, 2024 CVE-2024-10146
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Apr 17, 2024 CVE-2023-44227
Simple File List: A security weakness
Simple File List is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Oct 25, 2023 CVE-2023-39924
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Mar 27, 2023 CVE-2023-1025
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Oct 10, 2022 CVE-2022-3208
Simple File List: Cross-site request forgery
Simple File List is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Oct 10, 2022 CVE-2022-3207
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Sep 26, 2022 CVE-2022-3062
Simple File List: Cross-site scripting
Simple File List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 19, 2022 CVE-2022-1119
Simple File List: A security weakness
Simple File List is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
May 13, 2020 CVE-2020-12832
Simple File List: Arbitrary file deletion
Simple File List is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
See mitigation notes
CVE9.8
NVD9.8