Impact
The Simple File List WordPress plugin through version 6.3.11 performs a file‑move operation that fails to sanitize the source path provided by a user. Because the action is reachable without authentication, an attacker can supply arbitrary file paths, leading to the reading of any file on the server and the relocation of critical files outside the web root. This results in the disclosure of sensitive data and, if vital configuration files are moved, can allow a complete takeover of the site. The weakness is a classic Path Traversal flaw (CWE‑22).
Affected Systems
Any WordPress installation using the Simple File List plugin at or below version 6.3.11 is impacted. The vulnerability is exploitable in the context of a publicly reachable site that has the plugin enabled. Users of later plugin releases are not affected.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently low, but this small probability does not offset the potentially catastrophic impact. The plugin’s endpoint is accessible remotely, meaning that a simple HTTP request can trigger the flaw if the site is reachable from the internet. While the vulnerability is not listed in the CISA KEV catalog, its severity and the fact that it can be triggered by unauthenticated users make it a priority for remediation.
OpenCVE Enrichment