Simple File List
simple-file-list · plugin
Known security vulnerabilities for Simple File List. Find out in seconds which version runs on your site with WP Lens.
13 known vulnerabilities
2 critical · 9 exploitable without logging in · 4 with public exploit code · latest Jul 13, 2026
Closed on wordpress.org
Removed from the directory on Jul 23, 2026 · reason: security issue. A closed component gets no more updates; installed copies keep running and their vulnerabilities stay open. Remove it or replace it with a maintained alternative.
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2020-36847unauthenticated→ 4.2.3
Simple File List < 4.2.3 - Remote Code Execution
- Critical 9.8
CVE-2020-12832unauthenticated
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the applicatio
- High 7.5
CVE-2026-11912unauthenticated≤ 6.3.7
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
- High 7.5
CVE-2026-11911unauthenticated≤ 6.3.7
Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
- High 7.5
CVE-2025-54021unauthenticated≤ 6.1.14
WordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerability
- High 7.5
CVE-2023-44227unauthenticated≤ 6.1.9
WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion
- High 7.5
CVE-2022-1119unauthenticated≤ 3.2.7
Simple File List <= 3.2.7 - Arbitrary File Download
- High 7.1
CVE-2026-57382unauthenticated · needs a click≤ 6.3.8
WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-24953login required≤ 6.1.15
WordPress Simple File List plugin <= 6.1.15 - Arbitrary File Download vulnerability
- Medium 6.5
CVE-2026-12119contributor+≤ 6.3.7
Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via '
- Medium 5.4
CVE-2025-68591login required≤ 6.1.18
WordPress Simple File List plugin <= 6.1.18 - Broken Access Control vulnerability
- Medium 5.3
CVE-2025-47450unauthenticated≤ 6.1.13
WordPress Simple File List plugin <= 6.1.13 - Settings Change Vulnerability
- Medium 4.8
CVE-2023-39924admin≤ 6.1.9
WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Cross Site Scripting (XSS)
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).