PT-2026-78285 · WordPress · Simple File List

·

CVE-2026-16616

·

Published

2026-08-19

·

Updated

2026-08-27

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple File List WordPress plugin versions prior to 6.3.12
Description Unauthenticated users can exploit a lack of validation in the source path of a file-move operation. This allows an attacker to read arbitrary files on the server and relocate critical files outside of the web root, which may result in the disclosure of sensitive information and a complete site takeover.
Recommendations Update the Simple File List WordPress plugin to version 6.3.12 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16616

Affected Products

Simple File List