PT-2026-78285 · WordPress · Simple File List
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Simple File List WordPress plugin versions prior to 6.3.12
Description
Unauthenticated users can exploit a lack of validation in the source path of a file-move operation. This allows an attacker to read arbitrary files on the server and relocate critical files outside of the web root, which may result in the disclosure of sensitive information and a complete site takeover.
Recommendations
Update the Simple File List WordPress plugin to version 6.3.12 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple File List