CVE-2025-68591
8.1Mitchell Bennis · Simple File List
A missing authorization vulnerability in the Mitchell Bennis Simple File List plugin allows authenticated users to exploit incorrectly configured access controls.
Executive summary
A missing authorization vulnerability in the Mitchell Bennis Simple File List plugin for WordPress allows authenticated users to bypass access controls, posing a significant security risk.
Vulnerability
This is a missing authorization flaw (CWE-862) within the plugin that permits an authenticated user to perform unauthorized actions due to improper access control enforcement. The vulnerability is triggered via network access and requires low privileges to execute.
Business impact
Successful exploitation of this vulnerability could allow an attacker to modify or delete files depending on the specific access control misconfiguration. Given the CVSS score of 8.1, this is a High severity issue that could lead to unauthorized data manipulation or service disruption, potentially impacting the integrity and availability of the host WordPress environment.
Remediation
Immediate Action: Review the official Patchstack advisory for the latest security updates and apply them as soon as they become available. If a patch is not yet released, consider restricting access to the plugin settings to trusted administrative roles only.
Proactive Monitoring: Monitor server access logs for anomalous requests directed at the Simple File List plugin endpoints and investigate any unauthorized attempts to modify file structures.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin-specific file management parameters.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing the Mitchell Bennis Simple File List plugin should prioritize this vulnerability due to its high CVSS score. Administrators must actively monitor for vendor security updates and apply them immediately upon release to prevent potential unauthorized access to file management functions.
More Mitchell Bennis CVEs
Sources
Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.