PT-2026-51133 · WordPress · Simple File List
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Simple File List versions prior to 6.3.8
Description
The Simple File List plugin for WordPress contains a flaw where a missing authorization check on the
frontmanage shortcode attribute allows authenticated attackers with contributor-level access or higher to perform unauthorized file operations. These operations include deleting, moving, creating folders, and downloading files. An attacker can exploit this by creating a draft post with the eeSFL shortcode and using the post preview endpoint to obtain a nonce, which is a unique token used to prevent cross-site request forgery, to authorize requests that bypass checks in the includes/ee-list-ops-bar-process.php file.Recommendations
Update to a version later than 6.3.7.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple File List