WordPress Simple File List before 3.2.8 is vulnerable to local file inclusion via the eeFile parameter in the ~/includes/ee-downloader.php due to missing controls which make it possible for unauthenticated attackers retrieve arbitrary files.
View the template here CVE-2022-1119.yaml
References:
https://wpscan.com/vulnerability/075a3cc5-1970-4b64-a16f-3ec97e22b606