Sceawere

Vulnerability Detail

CVE-2026-39792UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Arbitrary File Deletion

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
16h ago
Vendor
Mitchell Bennis
Product
Simple File List
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-06T09:17:52.080Z",
  "pubdate": "2026-10-06T09:17:52.080Z",
  "executiveSummary": "The Simple File List plugin for WordPress, specifically versions 6.3.11 and below, contains a critical security vulnerability involving unauthenticated arbitrary file deletion.\nThe vulnerability originates from a failure to perform adequate input validation and authorization checks on file deletion requests processed by the plugin.\nThis flaw allows remote, unauthenticated attackers to delete arbitrary files from the underlying server filesystem, provided the web server process has sufficient file system permissions.\nThe impact of this vulnerability is severe, as it facilitates complete denial of service (DoS) by removing essential configuration files (e.g., wp-config.php), application source code, or critical system files.\nThere are no requirements for authentication or elevated privileges, significantly lowering the barrier for exploitation.\nThis vulnerability poses a substantial risk to the availability and integrity of the affected WordPress instance.",
  "technicalDetails": "The vulnerability resides within the request handling mechanism of the Simple File List plugin, which fails to verify the identity and authorization level of the user initiating a file deletion request.\nSpecifically, the plugin processes deletion requests through an endpoint that does not implement nonce validation or capability checks, allowing any external entity to trigger the deletion logic.\nThe root cause is an insecure implementation of the file removal process, which processes a user-supplied file path argument without properly sanitizing the input or verifying that the targeted file is restricted to the intended plugin directory.\nAn attacker can exploit this by crafting a malicious HTTP request directed at the vulnerable endpoint. By manipulating the path parameter (e.g., directory traversal via ../ sequences), an attacker can escape the intended root directory to delete sensitive files outside the scope of the plugin.\nAttack flow: 1. The attacker identifies the vulnerable endpoint responsible for file management in the Simple File List plugin. 2. The attacker constructs a request containing a path traversal payload designed to target a critical system or WordPress configuration file. 3. Because the endpoint lacks authentication and authorization enforcement, the server processes the request. 4. The underlying PHP process executes the file deletion function (such as unlink()) using the unsanitized path supplied by the attacker. 5. The target file is permanently removed from the filesystem.\nThis vulnerability is classified as critical because it allows for unauthenticated remote code execution or complete system disruption. By deleting critical files such as wp-config.php, an attacker can force a site to enter an installation state, potentially leading to a complete compromise of the database or administrative takeover. Furthermore, this vulnerability exposes the server to file-based DoS attacks, disrupting business operations and service availability."
}
CVE-2026-39792: Unauthenticated Arbitrary File Deletion (HIGH Severity, CVSS: 8.6) | Sceawere