WordPress · Simple File List · CVE-2026-16617
**Name of the Vulnerable Software and Affected Versions**
Simple File List WordPress plugin versions prior to 6.3.12
**Description**
Stored Cross-Site Scripting (XSS) occurs when the plugin fails to properly sanitize and escape a file's description before displaying it on the public file list. When front-end file management is enabled, unauthenticated users can inject malicious scripts that execute in the browser of any visitor viewing the list.
**Recommendations**
Update the Simple File List WordPress plugin to version 6.3.12 or later.