๐Ÿ” CVE Alert

CVE-2026-16616

UNKNOWN 0.0

Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

Vendor unknown
Product simple file list
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simple file list

Be the first to know when new unknown vulnerabilities affecting unknown simple file list are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simple File List
0 โ‰ค 6.3.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9631c97e-42e5-43b0-8998-e106f474ffba/

Credits

Sanjar Tulkinov WPScan