CVE · High

CVE-2026-57382 — Simple File List [simple-file-list] < 6.3.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57382 Simple File List [simple-file-list] < 6.3.9 High 7.1 < 6.3.9 6.3.9 2026-07-07

CVE-2026-57382

The Simple File List plugin for WordPress contains a security flaw in versions 6.3.8 and earlier, allowing malicious actors to inject unauthorized code into website pages by manipulating input data without proper filtering or encoding, which can be exploited through carefully crafted links that users may click on. This vulnerability enables unauthenticated attackers to execute arbitrary web scripts, potentially leading to further security breaches.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.