Impact
The Simple File List plugin for WordPress suffers from an improper neutralization of input during web page generation, resulting in a reflected XSS flaw. This weakness permits malicious script code to be included in the plugin’s output without proper encoding, which could lead to client‑side code execution, session hijacking, or phishing when viewed by affected users. The issue is identified as CWE‑79 and is rated with a CVSS score of 7.1.
Affected Systems
The vulnerability affects all installations of the Mitchell Bennis Simple File List plugin up to and including version 6.3.8. WordPress sites that have this plugin version deployed are at risk; no other WordPress components are explicitly mentioned as impacted by this issue.
Risk and Exploitability
The EPSS score is less than 1 % at the time of this analysis, indicating a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the CVSS score of 7.1 signifies substantial impact if exploited. It is inferred that an attacker could trigger the flaw by loading a crafted URL or submitting a crafted form that contains malicious script, and the plugin likely reflects that input back in the response. Because the input is not authenticated, the vulnerability is suitable for widespread phishing or exploitation campaigns.
OpenCVE Enrichment