
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68591 is a Missing Authorization vulnerability in the Simple File List WordPress plugin developed by Mitchell Bennis. It allows low-privileged authenticated attackers to exploit incorrectly configured access control security levels, affecting Simple File List versions from n/a through 6.1.18 (per NVD) or through 6.1.15 (per ENISA/Patchstack). The vulnerability was published on December 24, 2025, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to file management functionality. An attacker with a low-privilege WordPress account (e.g., subscriber or contributor role) can send crafted network requests to the plugin's endpoints to access or modify files beyond their intended authorization scope. No special conditions or complex attack chains are required — the attack vector is network-based, requires low privileges, no user interaction, and low attack complexity (Feedly).
Successful exploitation allows low-privileged attackers to access sensitive files and directories without proper authorization, retrieve confidential information stored within the plugin's managed file space, and modify or corrupt file contents. The integrity and availability impacts are both rated Low, with no direct confidentiality impact per the CVSS scoring, though practical exploitation could expose sensitive uploaded files depending on site configuration. The scope is limited to the affected WordPress installation and does not inherently enable lateral movement beyond the web application context (Feedly).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the disclosure date (Feedly). The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
https://target.com/wp-content/plugins/simple-file-list/readme.txt.wp-admin/admin-ajax.php with Simple File List action parameters from unexpected or low-privilege user accounts.wp-content/uploads/simple-file-list/ or similar).The primary remediation is to update the Simple File List plugin to a version beyond 6.1.18 (or 6.1.15 per Patchstack) that includes the authorization fix. Site administrators should review and restrict WordPress user registration if not required, and audit file access permissions within the plugin's managed directories. As a temporary workaround, consider deactivating the plugin until a patched version is confirmed installed. Implementing a Web Application Firewall (WAF) rule to restrict access to Simple File List plugin endpoints for non-administrator roles can provide additional defense-in-depth (Feedly, Patchstack).
The vulnerability was reported by Patchstack and received limited but standard coverage from automated vulnerability tracking platforms including Vulners, VulDB, and The Hacker Wire shortly after disclosure on December 24, 2025. Social media mentions were observed on Mastodon and Bluesky via The Hacker Wire account, indicating routine community awareness rather than significant concern. No notable researcher commentary or vendor statements beyond the initial Patchstack disclosure have been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."