← Πίσω στην αναζήτηση CVE

CVE-2026-12119

Περιγραφή

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the -frontmanage- shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform arbitrary file operations including deletion, move, folder creation, and download. An attacker can create a draft post containing the -eeSFL- shortcode, render it via the post preview endpoint to harvest the nonce needed to authorize the operations, and then submit file operation requests that bypass the intended authorization checks in includes/ee-list-ops-bar-process.php.

CVSS 6.5EPSS 0.46699999999999997%Κίνδυνος 0.68
Προβολή πηγής
Δημοσίευση
2026-06-20 09:16:15
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N