Impact
The vulnerability is a path traversal flaw that grants an attacker the ability to delete arbitrary files hosted on the web server while interacting with the Simple File List plugin. The flaw stems from the plugin’s failure to properly validate input file paths, allowing the construction of paths that reference files outside the intended directory. The result is loss or corruption of critical files, which could compromise site integrity and availability.
Affected Systems
WordPress sites running Mitchell Bennis Simple File List plugin version 6.3.11 or earlier. Any installation that has not upgraded beyond 6.3.11 is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is not available, but the lack of an authentication barrier makes exploitation trivial for anyone with web access. Although the vulnerability is not listed in the CISA KEV catalog, the ability to delete arbitrary files poses a significant risk of data loss or site disruption.
OpenCVE Enrichment