Arbitrary File Deletion in Simple File List Plugin for WordPress
CVE-2026-11911
7.5HIGH
What is CVE-2026-11911?
The Simple File List plugin for WordPress contains a vulnerability that permits arbitrary file deletion due to inadequate validation of file paths in the eeSFL_DeleteFile function. This issue affects all versions up to and including 6.3.7 and can be exploited by unauthenticated attackers to delete critical files on the server, such as wp-config.php. The vulnerability is further exacerbated as the simplefilelist_edit_job AJAX action is accessible without authentication through the wp_ajax_nopriv_ hook, bypassing the necessary access control checks that would typically protect against unauthorized access to the admin-ajax.php endpoint.
Affected Version(s)
Simple File List 0 <= 6.3.7