WordPress Plugin Vulnerabilities

Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description

Description

The plugin does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Ruwantha Harshamal
Submitter
Ruwantha Harshamal
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-19 (about 9 hours ago)

Other