SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16616

HIGH · CVSS 8.6 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Simple File List plugin for WordPress versions up to 6.3.11 is vulnerable due to inadequate validation of file-move operations, which can be exploited by unauthenticated users. This flaw allows attackers to read arbitrary files on the server and potentially relocate critical files outside the web root, resulting in sensitive information disclosure and a heightened risk of site takeover. WordPress site administrators using this plugin should prioritize immediate updates to mitigate these risks.

CVE
CVE-2026-16616
Severity
HIGH
CVSS
8.6
EPSS
0.54%
WordPress

Original NVD Description

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.