๐Ÿ” CVE Alert

CVE-2026-16617

UNKNOWN 0.0

Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.

Vendor unknown
Product simple file list
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simple file list

Be the first to know when new unknown vulnerabilities affecting unknown simple file list are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simple File List
0 โ‰ค 6.3.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fc51a940-8e67-45d0-b47d-b16da288ebb3/

Credits

Ruwantha Harshamal WPScan