Extension WordPress
Vulnérabilités Simple File List
Cette page rassemble les failles publiées pour Simple File List, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple File List
19 fiches
Simple File List <= 6.3.8 – Reflected Cross-Site Scripting
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-6.3.8
6.3.9
07/07/2026
Simple File List <= 6.3.7 – Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated…
*-6.3.7
6.3.8
19/06/2026
Simple File List <= 6.3.7 – Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers…
*-6.3.7
6.3.8
19/06/2026
Simple File List <= 6.3.7 – Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files…
*-6.3.7
6.3.8
19/06/2026
Simple File List <= 6.1.15 – Authenticated (Subscriber+) Arbitrary File Download
The Simple File List plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary…
*-6.1.15
6.1.16
09/02/2026
Simple File List <= 6.3.7 – Missing Authorization
The Simple File List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access…
*-6.3.7
6.3.8
25/12/2025
Simple File List <= 6.1.14 – Unauthenticated Arbitrary File Download
The Simple File List plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.14. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which…
*-6.1.14
6.1.15
28/07/2025
Simple File List <= 6.1.13 – Missing Authorization to Unauthenticated Minor Settings Update
The Simple File List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eeSFL_BASE_Setup() function in all versions up to, and including, 6.1.13. This makes it possible for unauthenticated…
*-6.1.13
6.1.14
07/05/2025
Simple File List <= 6.1.11 – Reflected Cross-Site Scripting
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-6.1.12
6.1.13
24/10/2024
Simple File List <= 6.1.9 – Authenticated (Administrator+) Stored Cross-Site Scripting via settings
The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-6.1.9
6.1.10
12/10/2023
Simple File List <= 6.1.9 – Unauthenticated Arbitrary File Deletion
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 6.1.9. This is due to insufficient controls on files passed to a deletion function. This makes it possible for…
*-6.1.9
6.1.10
28/09/2023
Simple File List <= 6.0.9 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-6.0.9
6.0.10
28/02/2023
Simple File List <= 4.4.12 – Cross-Site Request Forgery to Page Creation
The Simple File List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.12. This is due to missing or incorrect nonce validation on its page creation function eeSFL_FREE_CreatePostwithShortcode(). This makes it…
*-4.4.12
4.4.13
19/09/2022
Simple File List <= 4.4.11 – Reflected Cross-Site Scripting
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' and 'subtab' parameters in versions up to, and including, 4.4.11 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.4.11
4.4.12
19/09/2022
Simple File List <= 4.4.11 – Reflected Cross-Site Scripting
The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ and 'subtab' parameters in versions up to, and including, 4.4.11 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.4.11
4.4.12
26/08/2022
Simple File List < 4.2.3 – Remote Code Execution
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a…
[*, 4.2.3)
4.2.3
02/11/2020
Simple File List <= 4.2.7 – Arbitrary File Deletion
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.
*-4.2.7
4.2.8
16/05/2020
Simple File List <= 3.2.7 – Arbitrary File Download
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file…
*-3.2.7
3.2.8
23/05/2019
Simple File List <= 3.2.4 – Arbitrary File Deletion
The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2.4. This is due to the upward path traversal via the 'eeDeleteFile' parameter. This makes it possible for unauthenticated…
*-3.2.4
3.2.5
23/05/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.