CVE-2022-3208
The Simple File List plugin before version 4.4.13 contains a cross-site request forgery vulnerability in its page creation functionality. An attacker can exploit insufficient nonce validation in the eeSFL_FREE_CreatePostwithShortcode function to create arbitrary pages and modify their content without authorization. This requires tricking an authenticated administrator into clicking a malicious link, after which unauthenticated attackers gain the ability to perform these actions.
Based on public CVE data (MITRE/NVD).