CVE-2025-68591

WordPress Simple File List plugin <= 6.1.15 - Broken Access Control vulnerability

Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.15.


We have discovered 2,241 live websites that are affected by CVE-2025-68591.

Run a Free Instant Scan




Affected Software

Product  Simple File List
Category Wordpress Plugins
Vulnerable Domains2,241 live websites (81% of Simple File List install base)
Vulnerable Versions
  • from 0 through 6.1.15
Vulnerable Versions Count41 versions ( 91% of all versions)



Details

  • Published - Dec 24, 2025
  • Updated - Jan 20, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-68591
United States591 websites



Germany220 websites
GB217 websites
Italy137 websites
France110 websites
Denmark98 websites
Netherlands82 websites
Spain70 websites
Canada63 websites
Switzerland59 websites

Website Distribution by TLD

Number of websites using CVE-2025-68591
.com518 websites
.org303 websites
.de152 websites
.it103 websites
.nl67 websites
.co.uk60 websites
.dk55 websites
.ch54 websites
.net50 websites
.fr47 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-68591

Top websites that are affected by CVE-2025-68591. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*****.gov United States***,***
*****************************.***.uk GB***,***
************.org United States***,***
*******************.org United States***,***
******.de United States***,***
**************.org United States***,***
****.****.********.edu United States***,***
********.org United States***,***
******.org Italy***,***
****.*******.gr Greece***,***
See full domain list

FAQ

A total of 2,241 websites have been identified as vulnerable to CVE-2025-68591, based on global website indexing conducted by WebTechSurvey.
The Simple File List is affected by the CVE-2025-68591 vulnerability.
Simple File List versions up to and including 6.1.15 are vulnerable to CVE-2025-68591.