CVE-2026-16616
Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
| Vendor | unknown |
| Product | simple file list |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown simple file list
Be the first to know when new unknown vulnerabilities affecting unknown simple file list are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Simple File List
0 โค 6.3.11
References
Credits
Sanjar Tulkinov WPScan