What is CVE-2026-16616?
CVE-2026-16616 is a path traversal vulnerability in the Simple File List WordPress plugin (through version 6.3.11) that allows unauthenticated users to read arbitrary files on the server and relocate critical files outside the web root via an unvalidated file-move operation. This leads to sensitive information disclosure; immediate update to the latest patched version is recommended.
Azərbaycanca: CVE-2026-16616, Simple File List WordPress plugin-in 6.3.11-ə qədər versiyalarında autentifikasiya olunmamış istifadəçilərə icazəsiz fayl köçürmə əməliyyatı vasitəsilə serverdəki ixtiyari faylları oxumağa və həssas faylları web root-dan kənara daşımağa imkan verən path traversal zəifliyidir. Bu, məxfi məlumatların ifşasına səbəb olur. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the Simple File List plugin are affected by CVE-2026-16616?
The vulnerability affects versions up to and including 6.3.11 of the Simple File List plugin.
Does exploiting CVE-2026-16616 require the attacker to be authenticated?
No, unauthenticated users can exploit the path traversal vulnerability to read arbitrary files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.