CVE-2026-57382
The Simple File List plugin for WordPress contains a security flaw in versions 6.3.8 and earlier, allowing malicious actors to inject unauthorized code into website pages by manipulating input data without proper filtering or encoding, which can be exploited through carefully crafted links that users may click on. This vulnerability enables unauthenticated attackers to execute arbitrary web scripts, potentially leading to further security breaches.
Based on public CVE data (MITRE/NVD).