WordPress Simple File List before 3.2.8 is vulnerable to local file inclusion via the eeFile parameter in the ~/includes/ee-downloader.php due to missing controls which make it possible for unauthenticated attackers retrieve arbitrary files.
id: CVE-2022-1119
info:
name: WordPress Simple File List <3.2.8 - Local File Inclusion
author:
...