PT-2026-78286 · WordPress · Simple File List
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simple File List WordPress plugin versions prior to 6.3.12
Description
Stored Cross-Site Scripting (XSS) occurs when the plugin fails to properly sanitize and escape a file's description before displaying it on the public file list. When front-end file management is enabled, unauthenticated users can inject malicious scripts that execute in the browser of any visitor viewing the list.
Recommendations
Update the Simple File List WordPress plugin to version 6.3.12 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple File List