CVSS v3
7.5
HIGH
EPSS Score
90.6%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.
Active exploitation of CVE-2022-1119 has not been confirmed. The EPSS score is 90.6%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2022-1119 has a CVSS v3 base score of 7.5 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).