The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
We have discovered 2,220 live websites that are affected by CVE-2026-16616.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,220 live websites (100% of Simple File List install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 53 versions ( 100% of all versions) |
| 552 websites | |
| 237 websites | |
| 219 websites | |
| 122 websites | |
| 119 websites | |
| 87 websites | |
| 82 websites | |
| 81 websites | |
| 61 websites | |
| 61 websites |
| .com | 521 websites |
| .org | 284 websites |
| .de | 168 websites |
| .it | 90 websites |
| .nl | 68 websites |
| .co.uk | 56 websites |
| .ch | 55 websites |
| .fr | 52 websites |
| .net | 45 websites |
| .se | 44 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.de | **,*** | ||
| ****.*****.gov | ***,*** | ||
| ****.org | ***,*** | ||
| *****************************.***.uk | ***,*** | ||
| **************.com | ***,*** | ||
| *************.com | ***,*** | ||
| ******.org | ***,*** | ||
| ************.org | ***,*** | ||
| *******************.org | ***,*** | ||
| ******.de | ***,*** |
FAQ