SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16617

HIGH · CVSS 8.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Simple File List plugin for WordPress versions up to 6.3.11 is vulnerable due to inadequate sanitization and escaping of file descriptions, which can lead to Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows unauthenticated users to inject malicious scripts that execute in the browsers of visitors viewing the public file list. WordPress site administrators using this plugin should prioritize remediation to protect their users from potential exploitation.

CVE
CVE-2026-16617
Severity
HIGH
CVSS
8.8
EPSS
0.34%
WordPress

Original NVD Description

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.