CVE-2026-12119
The Simple File List plugin for WordPress has a security flaw affecting all versions up to 6.3.7. A contributor-level user or higher can exploit this issue by creating a draft post with a specific shortcode, then accessing the post preview endpoint to obtain a required authorization token. This allows them to bypass intended access controls and perform arbitrary file operations such as deletion, moving files, creating folders, and downloading files without proper permission.
Based on public CVE data (MITRE/NVD).