CVE-2026-16616 PUBLISHED

Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal

Assigner: WPScan
Reserved: 22.07.2026 Published: 19.08.2026 Updated: 19.08.2026

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

Product Status

Vendor Unknown
Product Simple File List
Versions Default: unknown
  • affected from 0 to 6.3.11 (incl.)

Credits

  • Sanjar Tulkinov finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE