Security Advisory

CVE-2023-4297

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-11-27 16:22:01
Last updated 2025-06-05 14:01:19
Assigner WPScan
State PUBLISHED

Description

The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.