CVE · Medium

CVE-2022-3208 — Simple File List [simple-file-list] < 4.4.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3208 Simple File List [simple-file-list] < 4.4.13 Cross-Site Request Forgery (CSRF) Medium 6.5 < 4.4.13 4.4.13 2022-09-19

CVE-2022-3208

The Simple File List plugin before version 4.4.13 contains a cross-site request forgery vulnerability in its page creation functionality. An attacker can exploit insufficient nonce validation in the eeSFL_FREE_CreatePostwithShortcode function to create arbitrary pages and modify their content without authorization. This requires tricking an authenticated administrator into clicking a malicious link, after which unauthenticated attackers gain the ability to perform these actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.