
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24953 is a Path Traversal (Arbitrary File Download) vulnerability in the WordPress plugin Simple File List by Mitchell Bennis. It allows authenticated attackers with low privileges (Subscriber-level) to download arbitrary files from the affected WordPress installation, including sensitive files such as credentials or backups. The vulnerability affects Simple File List versions up to and including 6.1.15, and was patched in version 6.1.16. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly). The vulnerability was reported on November 25, 2025, and published by Patchstack on February 9, 2026.
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The plugin fails to properly sanitize or restrict file path inputs, allowing an authenticated attacker to craft requests that traverse outside the intended directory and access arbitrary files on the server's filesystem. Exploitation requires a low-privilege authenticated account (e.g., Subscriber role) and no user interaction, making it accessible to any registered WordPress user. Attack patterns associated with this vulnerability include path traversal via encoded slashes and alternate encoding techniques (CAPEC-126, CAPEC-64, CAPEC-76, CAPEC-78, CAPEC-79) (Patchstack, Feedly).
Successful exploitation results in a high confidentiality impact — attackers can read and download arbitrary files from the web server, including WordPress configuration files (e.g., wp-config.php) containing database credentials, backup archives, private keys, or other sensitive data. Integrity and availability are not directly impacted by this vulnerability. However, credential exposure from downloaded configuration files could enable further compromise, including database access or full site takeover (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack, Feedly).
https://target.com/wp-content/plugins/simple-file-list/readme.txt.../../wp-config.php or URL-encoded equivalents such as %2e%2e%2f) to escape the plugin's intended directory.wp-config.php) to extract database credentials, authentication keys, or other sensitive configuration data for further exploitation (Patchstack).../, %2e%2e%2f, or %2e%2e/ in file path parameters; requests for sensitive files like wp-config.php originating from authenticated low-privilege sessions.wp-config.php, .env, or backup files in server access logs.Update the Simple File List WordPress plugin to version 6.1.16 or later, which contains the patch for this vulnerability. If an immediate update is not possible, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. Site administrators should also review user registration settings and restrict Subscriber-level account creation if not required. Contacting your hosting provider or web developer for assistance is recommended if self-remediation is not feasible (Patchstack).
Patchstack, which discovered and disclosed the vulnerability (credited to researcher 'daroo'), classifies it as high priority and warns that similar path traversal vulnerabilities are frequently leveraged in mass-exploit campaigns against WordPress sites. The vulnerability was also covered in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of February 9–15, 2026, indicating broad awareness within the WordPress security community (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."