Summary
CVE-2026-11912 is a Missing Authorization vulnerability (CWE-862) in the Simple File List plugin for WordPress, affecting all versions up to and including 6.3.7. Rated HIGH severity with a CVSS v3.1 base score of 7.5, the flaw enables fully unauthenticated remote attackers to modify and delete arbitrary files on the server — including critical files such as wp-config.php — with no credentials and no user interaction required. A public proof-of-concept has been published. The vendor released a patched version (6.3.8) on June 19, 2026, and immediate upgrading is strongly recommended.
Technical details
- Root cause: The plugin registers its
simplefilelist_edit_jobAJAX handler on both the authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) WordPress hooks. The authorization guard relies onis_admin(), which always returnsfalseduring AJAX requests, causing it to short-circuit before any proper capability check — or theAllowFrontManageadministrator setting — is ever evaluated. - Trigger conditions: No authentication, special configuration, or user interaction is required. The flaw is exploitable in all default installations regardless of whether
AllowFrontManagehas been enabled by the site administrator. - Attack vector: An unauthenticated remote attacker extracts a valid nonce from the plugin’s publicly accessible frontend HTML source, then sends crafted POST requests to
/wp-admin/admin-ajax.phpwith thesimplefilelist_edit_jobaction to perform arbitrary file operations on the server. - Impact: Unauthenticated arbitrary file modification and deletion. Path traversal in filename parameters allows attackers to target files outside the plugin’s storage directory, including
wp-config.php. Deletion ofwp-config.phptriggers WordPress’s reinstallation flow, which can be weaponized for full site takeover. Modification of existing files can be used to plant malicious content.
Affected software
- Simple File List WordPress Plugin: all versions up to and including 6.3.7
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade to Simple File List version 6.3.8 or later. The 6.3.8 release replaces the broken
is_admin()authorization guard with a propercurrent_user_can('manage_options')capability check in the front-end file management handler, adds arealpath()confinement check as defense-in-depth against path traversal, and restricts theeeSubFolderPOST parameter that previously expanded the path traversal attack surface. - If immediate patching is not feasible: Disable the plugin entirely until the upgrade can be applied. As an additional measure, restrict unauthenticated access to
/wp-admin/admin-ajax.phpat the web server or WAF level.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

