What is CVE-2026-16617?
The Simple File List WordPress plugin up to version 6.3.11 fails to properly sanitize and escape file descriptions before outputting them on the public file list. This allows unauthenticated users to perform Stored Cross-Site Scripting (XSS) attacks when front-end file management is enabled. Updating the plugin or disabling front-end file management is recommended.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Simple File List plugin are affected by CVE-2026-16617?
This vulnerability affects Simple File List WordPress plugin versions up to 6.3.11.
Under what condition can this Stored XSS vulnerability be exploited?
The Stored XSS attack can be performed by unauthenticated users via file descriptions when front-end file management is enabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.