WordPress Plugin Vulnerabilities

Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal

Description

The plugin does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Sanjar Tulkinov
Submitter
Sanjar Tulkinov
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-19 (about 9 hours ago)

Other