Executive brief
Simple File List, a WordPress plugin used to manage and display files on websites, contains a security flaw that allows attackers to inject malicious scripts. By tricking a site administrator or visitor into clicking a specially crafted link, an attacker could execute code in their browser. This could lead to unauthorized actions, theft of session information, or the display of fraudulent content on the site.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Mitchell Bennis Simple File List plugin (simple-file-list) for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows unauthenticated remote attackers to execute arbitrary JavaScript in the context of a user's browser session. Exploitation requires a victim to interact with a malicious link or crafted request (User Interaction required). This can result in session hijacking, unauthorized administrative actions if the victim is an admin, or website defacement. The issue is fixed in version 6.3.9.
Affected products
- Mitchell Bennis Simple File List <= 6.3.8
Timeline
- 2026-06-20: other: Reported by Nguyen Ba Khanh
- 2026-07-07: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD