Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple File List plugin for WordPress suffers from an improper neutralization of input during web page generation, resulting in a reflected XSS flaw. This weakness permits malicious script code to be included in the plugin’s output without proper encoding, which could lead to client‑side code execution, session hijacking, or phishing when viewed by affected users. The issue is identified as CWE‑79 and is rated with a CVSS score of 7.1.

Affected Systems

The vulnerability affects all installations of the Mitchell Bennis Simple File List plugin up to and including version 6.3.8. WordPress sites that have this plugin version deployed are at risk; no other WordPress components are explicitly mentioned as impacted by this issue.

Risk and Exploitability

The EPSS score is less than 1 % at the time of this analysis, indicating a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the CVSS score of 7.1 signifies substantial impact if exploited. It is inferred that an attacker could trigger the flaw by loading a crafted URL or submitting a crafted form that contains malicious script, and the plugin likely reflects that input back in the response. Because the input is not authenticated, the vulnerability is suitable for widespread phishing or exploitation campaigns.

Generated by OpenCVE AI on July 31, 2026 at 12:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Simple File List plugin to a version newer than 6.3.8 to ensure proper input sanitization.
  • If an upgrade is not immediately feasible, restrict the plugin’s use to trusted administrators only and disable its public‑facing pages until the fix is applied.
  • Deploy a Content Security Policy that disallows inline scripts or restricts script sources to mitigate reflected XSS while waiting for the official patch.

Generated by OpenCVE AI on July 31, 2026 at 12:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Mitchell Bennis
Mitchell Bennis simple File List
Wordpress
Wordpress wordpress
Vendors & Products Mitchell Bennis
Mitchell Bennis simple File List
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.
Title WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Mitchell Bennis Simple File List
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:53.859Z

Reserved: 2026-06-24T12:46:01.632Z

Link: CVE-2026-57382

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:35.137Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')