CyberRota Analysis
AI-GeneratedThe Simple File List plugin for WordPress versions up to 6.3.11 is vulnerable due to inadequate sanitization and escaping of file descriptions, which can lead to Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows unauthenticated users to inject malicious scripts that execute in the browsers of visitors viewing the public file list. WordPress site administrators using this plugin should prioritize remediation to protect their users from potential exploitation.
Original NVD Description
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.