CVE-2025-47450
A security flaw exists in the Simple File List plugin for WordPress, where an oversight has left its core setup function susceptible to tampering by unauthorized parties without proper authentication checks. Specifically, versions 6.1.13 and earlier are affected, allowing attackers to manipulate a crucial language setting without needing valid credentials. This vulnerability enables malicious actors to alter the plugin's behavior in unintended ways.
Based on public CVE data (MITRE/NVD).