PLUGIN SECURITY

Is Simple File List safe?

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.

What this plugin does

  • Slug: simple-file-list
  • Author: Really Simple Plugins
  • 3000000+ active installs
  • 98/100 rating (8861 reviews on wordpress.org)
  • 216552046 all-time downloads
  • On WordPress.org since 2015-03-15

2FAhttpssecuritytwo factorvulnerabilities

Maintenance status

  • Latest known version: 9.7.0
  • Last updated: 2026-08-24 9:03am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

21 known CVEs on file for Simple File List. Reported between 2019 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16617 Simple File List [simple-file-list] <= 6.3.11 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 6.3.11 6.3.11 2026-08-19 ✓ fixed in latest
CVE-2026-16616 Simple File List [simple-file-list] <= 6.3.11 (unfixed) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 6.3.11 6.3.11 2026-08-19 ✓ fixed in latest
CVE-2026-57382 Simple File List [simple-file-list] < 6.3.9 High 7.1 < 6.3.9 6.3.9 2026-07-07 ✓ fixed in latest
CVE-2026-12119 Simple File List [simple-file-list] < 6.3.8 Missing Authorization Medium 6.5 < 6.3.8 6.3.8 2026-06-19 ✓ fixed in latest
CVE-2026-11911 Simple File List [simple-file-list] < 6.3.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 6.3.8 6.3.8 2026-06-19 ✓ fixed in latest
CVE-2026-11912 Simple File List [simple-file-list] < 6.3.8 Missing Authorization High 7.5 < 6.3.8 6.3.8 2026-06-19 ✓ fixed in latest
CVE-2026-24953 Simple File List [simple-file-list] < 6.1.16 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 6.1.16 6.1.16 2026-02-09 ✓ fixed in latest
Simple File List [simple-file-list] <= 6.1.18 (unfixed) Missing Authorization Medium 5.4 < 6.1.18 6.1.18 2025-12-24 ✓ fixed in latest
+ 24 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-54021 Simple File List [simple-file-list] < 6.1.15 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 6.1.15 6.1.15 2025-07-28 ✓ fixed in latest
CVE-2025-34085 Simple File List [simple-file-list] < 4.2.3 Missing Authentication for Critical Function Unknown < 4.2.3 4.2.3 2025-07-09 ✓ fixed in latest
CVE-2025-47450 Simple File List [simple-file-list] < 6.1.14 Missing Authorization Medium 5.3 < 6.1.14 6.1.14 2025-05-07 ✓ fixed in latest
CVE-2024-10146 Simple File List [simple-file-list] < 6.1.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.1.13 6.1.13 2024-10-24 ✓ fixed in latest
CVE-2023-39924 Simple File List [simple-file-list] < 6.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 6.1.10 6.1.10 2023-10-12 ✓ fixed in latest
CVE-2023-44227 Simple File List [simple-file-list] < 6.1.10 Missing Authorization High 7.5 < 6.1.10 6.1.10 2023-09-28 ✓ fixed in latest
CVE-2023-1025 Simple File List [simple-file-list] < 6.0.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 6.0.10 6.0.10 2023-02-28 ✓ fixed in latest
CVE-2022-3208 Simple File List [simple-file-list] < 4.4.13 Cross-Site Request Forgery (CSRF) Medium 6.5 < 4.4.13 4.4.13 2022-09-19 ✓ fixed in latest
CVE-2022-3207 Simple File List [simple-file-list] < 4.4.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.4.12 4.4.12 2022-09-19 ✓ fixed in latest
CVE-2022-3062 Simple File List [simple-file-list] < 4.4.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.4.12 4.4.12 2022-08-26 ✓ fixed in latest
CVE-2020-36847 Simple File List [simple-file-list] < 4.2.3 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 4.2.3 4.2.3 2020-11-02 ✓ fixed in latest
CVE-2020-12832 Simple File List [simple-file-list] < 4.2.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 4.2.8 4.2.8 2020-05-13 ✓ fixed in latest
Simple File List [simple-file-list] < 4.2.3 Unknown < 4.2.3 4.2.3 2020-04-27 ✓ fixed in latest
Simple File List [simple-file-list] < 3.2.5 Unknown < 3.2.5 3.2.5 2019-05-27 ✓ fixed in latest
Simple File List [simple-file-list] < 3.2.5 Unknown < 3.2.5 3.2.5 2019-05-27 ✓ fixed in latest
CVE-2022-1119 Simple File List [simple-file-list] < 3.2.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 3.2.8 3.2.8 2019-05-23 ✓ fixed in latest
Simple File List [simple-file-list] < 3.2.5 Unknown < 3.2.5 3.2.5 2019-05-23 ✓ fixed in latest
Simple File List [simple-file-list] < 4.2.3 Unknown < 4.2.3 4.2.3 ✓ fixed in latest
Simple File List [simple-file-list] < 3.2.5 Unknown < 3.2.5 3.2.5 ✓ fixed in latest
Simple File List [simple-file-list] < 3.2.8 Unknown < 3.2.8 3.2.8 ✓ fixed in latest
Simple File List Plugin < 3.2.8 - Unauthenticated Arbitrary File Download Unknown < 3.2.8 3.2.8 ✓ fixed in latest
Simple File List Plugin <= 3.2.4 - Authenticated Arbitrary File Delete Unknown < 3.2.5 3.2.5 ✓ fixed in latest
Simple File List < 4.2.3 - Unauthenticated Arbitrary File Upload RCE Unknown < 4.2.3 4.2.3 ✓ fixed in latest
CVE-2025-68591 Simple File List < 6.3.8 - Missing Authorization Unknown < 6.3.8 6.3.8 ✓ fixed in latest

How to fix it

Keep Simple File List updated — 9.7.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.