WordPress Plugin Vulnerabilities
Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
Description
The plugin does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ruwantha Harshamal
Submitter
Ruwantha Harshamal
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-19 (about 9 hours ago)