Skip to content
Noroxi

Simple File List

simple-file-list · plugin

Known security vulnerabilities for Simple File List. Find out in seconds which version runs on your site with WP Lens.

13 known vulnerabilities

2 critical · 9 exploitable without logging in · 4 with public exploit code · latest Jul 13, 2026

Closed on wordpress.org

Removed from the directory on Jul 23, 2026 · reason: security issue. A closed component gets no more updates; installed copies keep running and their vulnerabilities stay open. Remove it or replace it with a maintained alternative.

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2020-36847unauthenticated→ 4.2.3

    Simple File List < 4.2.3 - Remote Code Execution

    Critical 9.8
  • CVE-2020-12832unauthenticated

    WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the applicatio

    Critical 9.8
  • CVE-2026-11912unauthenticated≤ 6.3.7

    Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action

    High 7.5
  • CVE-2026-11911unauthenticated≤ 6.3.7

    Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter

    High 7.5
  • CVE-2025-54021unauthenticated≤ 6.1.14

    WordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerability

    High 7.5
  • CVE-2023-44227unauthenticated≤ 6.1.9

    WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion

    High 7.5
  • CVE-2022-1119unauthenticated≤ 3.2.7

    Simple File List <= 3.2.7 - Arbitrary File Download

    High 7.5
  • CVE-2026-57382unauthenticated · needs a click≤ 6.3.8

    WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-24953login required≤ 6.1.15

    WordPress Simple File List plugin <= 6.1.15 - Arbitrary File Download vulnerability

    Medium 6.5
  • CVE-2026-12119contributor+≤ 6.3.7

    Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via '

    Medium 6.5
  • CVE-2025-68591login required≤ 6.1.18

    WordPress Simple File List plugin <= 6.1.18 - Broken Access Control vulnerability

    Medium 5.4
  • CVE-2025-47450unauthenticated≤ 6.1.13

    WordPress Simple File List plugin <= 6.1.13 - Settings Change Vulnerability

    Medium 5.3
  • CVE-2023-39924admin≤ 6.1.9

    WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Cross Site Scripting (XSS)

    Medium 4.8

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory

Simple File List — WordPress plugin vulnerabilities — Noroxi