CVE-2025-68591
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68591 is a Missing Authorization vulnerability in the Simple File List WordPress plugin developed by Mitchell Bennis. It allows low-privileged authenticated attackers to exploit incorrectly configured access control security levels, affecting Simple File List versions from n/a through 6.1.18 (per NVD) or through 6.1.15 (per ENISA/Patchstack). The vulnerability was published on December 24, 2025, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to file management functionality. An attacker with a low-privilege WordPress account (e.g., subscriber or contributor role) can send crafted network requests to the plugin's endpoints to access or modify files beyond their intended authorization scope. No special conditions or complex attack chains are required — the attack vector is network-based, requires low privileges, no user interaction, and low attack complexity (Feedly).

Impact

Successful exploitation allows low-privileged attackers to access sensitive files and directories without proper authorization, retrieve confidential information stored within the plugin's managed file space, and modify or corrupt file contents. The integrity and availability impacts are both rated Low, with no direct confidentiality impact per the CVSS scoring, though practical exploitation could expose sensitive uploaded files depending on site configuration. The scope is limited to the affected WordPress installation and does not inherently enable lateral movement beyond the web application context (Feedly).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the disclosure date (Feedly). The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Simple File List plugin version ≤ 6.1.18 using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/simple-file-list/readme.txt.
  2. Obtain low-privilege access: Register or obtain credentials for a low-privilege WordPress account (e.g., subscriber role), which may be available on sites with open registration.
  3. Identify vulnerable endpoints: Enumerate the plugin's AJAX actions or admin-ajax.php endpoints associated with Simple File List's file management features.
  4. Send unauthorized request: Craft and send an authenticated HTTP request (with valid nonce/cookie) to a restricted file management endpoint that lacks proper capability checks, bypassing the intended access control.
  5. Access or modify files: Depending on the endpoint reached, retrieve directory listings, download sensitive files, or overwrite existing file contents within the plugin's managed directories (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing repeated authenticated POST requests to wp-admin/admin-ajax.php with Simple File List action parameters from unexpected or low-privilege user accounts.
  • Logs: WordPress debug logs or error logs referencing Simple File List plugin functions being called by unauthorized user roles.
  • File System: Unexpected modifications to files within the Simple File List upload/managed directory (typically under wp-content/uploads/simple-file-list/ or similar).
  • File System: New or altered files in the plugin-managed directory with timestamps inconsistent with normal administrative activity.
  • Network: Unusual authenticated HTTP requests targeting Simple File List plugin endpoints from IP addresses not associated with known administrators.

Mitigation and workarounds

The primary remediation is to update the Simple File List plugin to a version beyond 6.1.18 (or 6.1.15 per Patchstack) that includes the authorization fix. Site administrators should review and restrict WordPress user registration if not required, and audit file access permissions within the plugin's managed directories. As a temporary workaround, consider deactivating the plugin until a patched version is confirmed installed. Implementing a Web Application Firewall (WAF) rule to restrict access to Simple File List plugin endpoints for non-administrator roles can provide additional defense-in-depth (Feedly, Patchstack).

Community reactions

The vulnerability was reported by Patchstack and received limited but standard coverage from automated vulnerability tracking platforms including Vulners, VulDB, and The Hacker Wire shortly after disclosure on December 24, 2025. Social media mentions were observed on Mastodon and Bluesky via The Hacker Wire account, indicating routine community awareness rather than significant concern. No notable researcher commentary or vendor statements beyond the initial Patchstack disclosure have been identified (Feedly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16974MEDIUM6.4
  • kirki
NoYesAug 11, 2026
CVE-2026-14549NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-14548NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management