Junglewise Threat Intelligence

CVE-2026-12119: eemitch Simple File List missing authorization in frontmanage shortcode

CVE-2026-12119 · Severity: medium · CVSS 6.5 · Published 2026-06-20

Technologies: Eemitch Simple File List. Vendors: Eemitch.

Executive brief

The Simple File List plugin for WordPress, which allows users to manage and share files on their website, contains a security flaw that allows unauthorized file management. Authenticated users with low-level permissions (such as contributors) can delete, move, or create folders and download files they should not have access to. This could lead to the loss of important website documents or unauthorized access to private files.

Technical details

A missing authorization check (CWE-862) exists in the 'frontmanage' shortcode attribute of the Simple File List plugin for WordPress. Authenticated attackers with contributor-level permissions or higher can exploit this by creating a draft post containing the 'eeSFL' shortcode. By viewing the post via the preview endpoint, the attacker can harvest the necessary security nonce. This nonce is then used to submit unauthorized file operation requests to 'includes/ee-list-ops-bar-process.php', bypassing intended access controls to delete, move, or create directories and download files. The vulnerability is present in all versions up to and including 6.3.7.

Affected products

  • eemitch Simple File List up to, and including, 6.3.7

Timeline

  • 2026-06-20: disclosed: Published by Wordfence and NVD

References

Related threats