CVE-2026-16617: Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Simple File Listto a version that resolves this vulnerability.Fixed in 6.3.11
Event History
Frequently Asked Questions
Which sites are exposed to unauthenticated exploitation?
Sites using Simple File List through version 6.3.11 are exposed when front-end file management is enabled. In that configuration, an unauthenticated user can submit a malicious file description.
Who is affected by the injected script?
The stored script executes in the browser of any visitor who views the public file list containing the malicious description.