PLUGIN SECURITY
Is Simple File List safe?
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
What this plugin does
- Slug:
simple-file-list - Author: Really Simple Plugins
- 3000000+ active installs
- 98/100 rating (8861 reviews on wordpress.org)
- 216552046 all-time downloads
- On WordPress.org since 2015-03-15
2FAhttpssecuritytwo factorvulnerabilities
Maintenance status
- Latest known version: 9.7.0
- Last updated: 2026-08-24 9:03am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
21 known CVEs on file for Simple File List. Reported between 2019 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-16617 | Simple File List [simple-file-list] <= 6.3.11 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 6.3.11 | 6.3.11 | 2026-08-19 | ✓ fixed in latest |
| CVE-2026-16616 | Simple File List [simple-file-list] <= 6.3.11 (unfixed) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Unknown | < 6.3.11 | 6.3.11 | 2026-08-19 | ✓ fixed in latest |
| CVE-2026-57382 | Simple File List [simple-file-list] < 6.3.9 | — | High 7.1 | < 6.3.9 | 6.3.9 | 2026-07-07 | ✓ fixed in latest |
| CVE-2026-12119 | Simple File List [simple-file-list] < 6.3.8 | Missing Authorization | Medium 6.5 | < 6.3.8 | 6.3.8 | 2026-06-19 | ✓ fixed in latest |
| CVE-2026-11911 | Simple File List [simple-file-list] < 6.3.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 6.3.8 | 6.3.8 | 2026-06-19 | ✓ fixed in latest |
| CVE-2026-11912 | Simple File List [simple-file-list] < 6.3.8 | Missing Authorization | High 7.5 | < 6.3.8 | 6.3.8 | 2026-06-19 | ✓ fixed in latest |
| CVE-2026-24953 | Simple File List [simple-file-list] < 6.1.16 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 6.1.16 | 6.1.16 | 2026-02-09 | ✓ fixed in latest |
| — | Simple File List [simple-file-list] <= 6.1.18 (unfixed) | Missing Authorization | Medium 5.4 | < 6.1.18 | 6.1.18 | 2025-12-24 | ✓ fixed in latest |
+ 24 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-54021 | Simple File List [simple-file-list] < 6.1.15 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 6.1.15 | 6.1.15 | 2025-07-28 | ✓ fixed in latest |
| CVE-2025-34085 | Simple File List [simple-file-list] < 4.2.3 | Missing Authentication for Critical Function | Unknown | < 4.2.3 | 4.2.3 | 2025-07-09 | ✓ fixed in latest |
| CVE-2025-47450 | Simple File List [simple-file-list] < 6.1.14 | Missing Authorization | Medium 5.3 | < 6.1.14 | 6.1.14 | 2025-05-07 | ✓ fixed in latest |
| CVE-2024-10146 | Simple File List [simple-file-list] < 6.1.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.1.13 | 6.1.13 | 2024-10-24 | ✓ fixed in latest |
| CVE-2023-39924 | Simple File List [simple-file-list] < 6.1.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 6.1.10 | 6.1.10 | 2023-10-12 | ✓ fixed in latest |
| CVE-2023-44227 | Simple File List [simple-file-list] < 6.1.10 | Missing Authorization | High 7.5 | < 6.1.10 | 6.1.10 | 2023-09-28 | ✓ fixed in latest |
| CVE-2023-1025 | Simple File List [simple-file-list] < 6.0.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 6.0.10 | 6.0.10 | 2023-02-28 | ✓ fixed in latest |
| CVE-2022-3208 | Simple File List [simple-file-list] < 4.4.13 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 4.4.13 | 4.4.13 | 2022-09-19 | ✓ fixed in latest |
| CVE-2022-3207 | Simple File List [simple-file-list] < 4.4.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.4.12 | 4.4.12 | 2022-09-19 | ✓ fixed in latest |
| CVE-2022-3062 | Simple File List [simple-file-list] < 4.4.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.4.12 | 4.4.12 | 2022-08-26 | ✓ fixed in latest |
| CVE-2020-36847 | Simple File List [simple-file-list] < 4.2.3 | Unrestricted Upload of File with Dangerous Type | Critical 9.8 | < 4.2.3 | 4.2.3 | 2020-11-02 | ✓ fixed in latest |
| CVE-2020-12832 | Simple File List [simple-file-list] < 4.2.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Critical 9.8 | < 4.2.8 | 4.2.8 | 2020-05-13 | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 4.2.3 | — | Unknown | < 4.2.3 | 4.2.3 | 2020-04-27 | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 3.2.5 | — | Unknown | < 3.2.5 | 3.2.5 | 2019-05-27 | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 3.2.5 | — | Unknown | < 3.2.5 | 3.2.5 | 2019-05-27 | ✓ fixed in latest |
| CVE-2022-1119 | Simple File List [simple-file-list] < 3.2.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 3.2.8 | 3.2.8 | 2019-05-23 | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 3.2.5 | — | Unknown | < 3.2.5 | 3.2.5 | 2019-05-23 | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 4.2.3 | — | Unknown | < 4.2.3 | 4.2.3 | — | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 3.2.5 | — | Unknown | < 3.2.5 | 3.2.5 | — | ✓ fixed in latest |
| — | Simple File List [simple-file-list] < 3.2.8 | — | Unknown | < 3.2.8 | 3.2.8 | — | ✓ fixed in latest |
| — | Simple File List Plugin < 3.2.8 - Unauthenticated Arbitrary File Download | — | Unknown | < 3.2.8 | 3.2.8 | — | ✓ fixed in latest |
| — | Simple File List Plugin <= 3.2.4 - Authenticated Arbitrary File Delete | — | Unknown | < 3.2.5 | 3.2.5 | — | ✓ fixed in latest |
| — | Simple File List < 4.2.3 - Unauthenticated Arbitrary File Upload RCE | — | Unknown | < 4.2.3 | 4.2.3 | — | ✓ fixed in latest |
| CVE-2025-68591 | Simple File List < 6.3.8 - Missing Authorization | — | Unknown | < 6.3.8 | 6.3.8 | — | ✓ fixed in latest |
How to fix it
Keep Simple File List updated — 9.7.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Wordfence Security – Firewall, Malware Scan, and Login Security — 5000000+ active installs — 94/100 (4979) — max PHP 8.4
- Hostinger Tools — 3000000+ active installs — 70/100 (40) — max PHP 8.4
- Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — 1000000+ active installs — 96/100 (1477) — max PHP 8.4
- Two Factor — 100000+ active installs — 96/100 (208) — max PHP 8.4
- WP 2FA – Two-factor authentication for WordPress — 100000+ active installs — 94/100 (176)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.