CVE-2026-24953: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24953 is a Path Traversal (Arbitrary File Download) vulnerability in the WordPress plugin Simple File List by Mitchell Bennis. It allows authenticated attackers with low privileges (Subscriber-level) to download arbitrary files from the affected WordPress installation, including sensitive files such as credentials or backups. The vulnerability affects Simple File List versions up to and including 6.1.15, and was patched in version 6.1.16. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly). The vulnerability was reported on November 25, 2025, and published by Patchstack on February 9, 2026.

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The plugin fails to properly sanitize or restrict file path inputs, allowing an authenticated attacker to craft requests that traverse outside the intended directory and access arbitrary files on the server's filesystem. Exploitation requires a low-privilege authenticated account (e.g., Subscriber role) and no user interaction, making it accessible to any registered WordPress user. Attack patterns associated with this vulnerability include path traversal via encoded slashes and alternate encoding techniques (CAPEC-126, CAPEC-64, CAPEC-76, CAPEC-78, CAPEC-79) (Patchstack, Feedly).

Impact

Successful exploitation results in a high confidentiality impact — attackers can read and download arbitrary files from the web server, including WordPress configuration files (e.g., wp-config.php) containing database credentials, backup archives, private keys, or other sensitive data. Integrity and availability are not directly impacted by this vulnerability. However, credential exposure from downloaded configuration files could enable further compromise, including database access or full site takeover (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Simple File List plugin at version 6.1.15 or earlier using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/simple-file-list/readme.txt.
  2. Obtain low-privilege credentials: Register or obtain a Subscriber-level (or higher) WordPress account on the target site, as exploitation requires authentication.
  3. Authenticate: Log in to the WordPress site to obtain a valid session cookie or nonce.
  4. Craft path traversal request: Send an authenticated HTTP request to the plugin's file download endpoint with a manipulated file path parameter using traversal sequences (e.g., ../../wp-config.php or URL-encoded equivalents such as %2e%2e%2f) to escape the plugin's intended directory.
  5. Retrieve sensitive files: Download the response containing the targeted file (e.g., wp-config.php) to extract database credentials, authentication keys, or other sensitive configuration data for further exploitation (Patchstack).

Indicators of compromise

  • Network: HTTP GET or POST requests to Simple File List plugin endpoints containing path traversal sequences such as ../, %2e%2e%2f, or %2e%2e/ in file path parameters; requests for sensitive files like wp-config.php originating from authenticated low-privilege sessions.
  • Logs: WordPress or web server access logs showing requests to plugin file-handling endpoints with unusual file path values referencing parent directories or system files outside the plugin's upload directory.
  • File System: No direct file system artifacts are created by read-only path traversal; however, monitor for unexpected access to wp-config.php, .env, or backup files in server access logs.
  • Process/Application: Repeated authenticated requests from the same user account targeting file download functionality with varying path parameters, potentially indicating automated scanning or exploitation attempts (Patchstack).

Mitigation and workarounds

Update the Simple File List WordPress plugin to version 6.1.16 or later, which contains the patch for this vulnerability. If an immediate update is not possible, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. Site administrators should also review user registration settings and restrict Subscriber-level account creation if not required. Contacting your hosting provider or web developer for assistance is recommended if self-remediation is not feasible (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability (credited to researcher 'daroo'), classifies it as high priority and warns that similar path traversal vulnerabilities are frequently leveraged in mass-exploit campaigns against WordPress sites. The vulnerability was also covered in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of February 9–15, 2026, indicating broad awareness within the WordPress security community (Wordfence, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management