CVE-2025-68591Missing Authorization in Bennis Simple File List

Severity
8.1HIGHNVD
EPSS
0.0%
top 87.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.18.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
WordPress Simple File List plugin <= 6.1.18 - Broken Access Control vulnerability2025-12-24
GHSA
GHSA-v4vp-c74m-hxxm: Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Secur2025-12-24

🕵️Threat Intelligence

1
Wiz
CVE-2025-68591 Impact, Exploitability, and Mitigation Steps | Wiz