Feed/CVE-2026-16616
CVE-2026-16616HIGHCVSS 8.6

CVE-2026-16616

Published Aug 19, 2026·Updated Aug 19, 2026

NVD Description

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free