Products

Showing 3 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
simplefilelist vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Simple File List < 4.2.3 - Remote Code Execution

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CWE-434Jul 12, 2025
CVSS9.8v3.1EPSS18%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Simple File List < 6.1.13 - Reflected Cross-Site Scripting

The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.

CWE-79Nov 14, 20241 related artifact
CVSS5.4v3.1EPSS0.57%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

simplefilelist simple-file-list Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CWE-22May 13, 20201 related artifact
CVSS9.8v3.1EPSS7.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX