Description

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

INFO

Published Date :

2025-07-12T09:24:28.215Z

Last Modified :

2026-04-08T17:11:48.634Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2020-36847 vulnerability.

Vendors Products
Simplefilelist
  • Simple File List

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact