Impact
The Simple File List WordPress plugin, versions up to 6.3.11, fails to escape or sanitize file descriptions before rendering them on the public file list. An attacker can supply a malicious description that persists in the plugin’s storage, and when any site visitor views the list, the injected code executes in their browser. This flaw grants arbitrary JavaScript execution in the context of the site’s domain, enabling cookie theft, session hijacking, or phishing, and represents a severe threat to confidentiality and integrity of site visitors.
Affected Systems
Any WordPress installation that has the Simple File List plugin version 6.3.11 or earlier and that has front‑end file management or a publicly visible file list enabled is impacted. The plugin is distributed by an unknown vendor; therefore any site owner should review their plugin version and front‑end settings.
Risk and Exploitability
This vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is listed as < 1 %, meaning widespread exploitation is considered unlikely, and it is not currently in the CISA KEV catalog. Nonetheless, the flaw is exploitable by unauthenticated users via the public file list, so the attack vector is direct and will not require additional credentials or privileges.
OpenCVE Enrichment