cleantalk
Vulnerabilities and Security Researches

Simple File List, CVE-2022-3208

CVE, Research URL

CVE-2022-3208

Application

Simple File List

Published on
Oct 11, 2022
Research Description
The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.
Affected versions
Min -, max 4.4.13.
Status
vulnerable