CVE-2023-4297: Mediamanifesto Mmm Simple File List

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.

Affected products

Published 2023-11-27. Last modified 2026-06-17.