Description
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
INFO
Published Date :
2025-07-12T09:24:28.215Z
Last Modified :
2026-04-08T17:11:48.634Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2020-36847 vulnerability.
| Vendors | Products |
|---|---|
| Simplefilelist |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2020-36847.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact