Description
WordPress Plugin Simple File List is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file download vulnerabilities. An attacker can exploit these vulnerabilities to delete arbitrary files or to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Simple File List version 3.2.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.5 or latest
References
https://docs.google.com/document/d/1qIZXTzEpI4tO6832vk1KfsSAroT0FY2l--THlhJ8z3c/edit
https://docs.google.com/document/d/11KLjuMaHLjPBf2R-Af1R01JNebD5mLRDBnCadmNmC_M/edit
https://plugins.svn.wordpress.org/simple-file-list/trunk/readme.txt
Related Vulnerabilities
IBM RTC Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7440)
Oracle Application Server Improper Authentication Vulnerability (CVE-2002-0563)
YOURLS Access of Resource Using Incompatible Type ('Type Confusion') Vulnerability (CVE-2019-14537)
WordPress Plugin Compact WP Audio Player Multiple Vulnerabilities (1.9.6)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Security Bypass (1.3.6.4)