WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.
https://github.com/0x05010705/simplefilelist1.7
https://wordpress.org/plugins/simple-file-list/#developers