Summary
CVE-2026-11911 is a high-severity unauthenticated arbitrary file deletion vulnerability in the Simple File List WordPress plugin, affecting all versions up to and including 6.3.7. The flaw stems from insufficient file path validation in the eeSFL_DeleteFile function (CWE-22), allowing any unauthenticated remote attacker to delete arbitrary files on the server. Deleting a critical file such as wp-config.php forces WordPress into reinstallation mode, creating a direct and well-understood path to full Remote Code Execution (RCE) and complete site takeover.
Technical details
- Root cause: Insufficient file path validation in the
eeSFL_DeleteFilefunction. TheeeSubFolderPOST parameter was accepted without proper path confinement, enabling directory traversal outside the intended file directory. - Authentication bypass: The
simplefilelist_edit_jobAJAX action is registered viawp_ajax_nopriv_, making it accessible to unauthenticated users. Anis_admin()guard intended to restrict access is inoperative in this context because WordPress’sadmin-ajax.phpendpoint always satisfies that check, regardless of the caller’s authentication state. - Attack vector: An unauthenticated HTTP POST request to
wp-admin/admin-ajax.phpwithaction=simplefilelist_edit_joband a crafted file path parameter. No credentials or user interaction are required. - Impact: Arbitrary deletion of any file accessible to the web server process. Deleting
wp-config.phpresets WordPress to its first-run installation state, which an attacker can immediately exploit to register a new administrative account and achieve full Remote Code Execution on the underlying server.
Affected software
- Simple File List WordPress plugin (by eemitch / Mitchell Bennis) — all versions up to and including 6.3.7
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Update the Simple File List plugin to version 6.3.8 or later. Version 6.3.8 replaces the broken
is_admin()authorization guard with a propercurrent_user_can('manage_options')capability check in the file management AJAX handler, removes acceptance of theeeSubFolderPOST parameter that enabled the path traversal, and adds arealpath()confinement check to the file delete function as defense-in-depth. - If immediate patching is not possible: Disable the Simple File List plugin until the update can be applied, or restrict unauthenticated external access to
wp-admin/admin-ajax.phpat the web server or WAF level.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

