CVE · Medium

CVE-2025-47450 — Simple File List [simple-file-list] < 6.1.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47450 Simple File List [simple-file-list] < 6.1.14 Missing Authorization Medium 5.3 < 6.1.14 6.1.14 2025-05-07

CVE-2025-47450

A security flaw exists in the Simple File List plugin for WordPress, where an oversight has left its core setup function susceptible to tampering by unauthorized parties without proper authentication checks. Specifically, versions 6.1.13 and earlier are affected, allowing attackers to manipulate a crucial language setting without needing valid credentials. This vulnerability enables malicious actors to alter the plugin's behavior in unintended ways.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.