GHSA-36w4-4687-hhqjHighCVSS 8.8

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file...

Published
August 19, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.

🔗 References (3)