CVE · Critical

CVE-2020-36847 — Simple File List [simple-file-list] < 4.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36847 Simple File List [simple-file-list] < 4.2.3 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 4.2.3 4.2.3 2020-11-02

CVE-2020-36847

The Simple File List plugin through version 4.2.2 contains a remote code execution vulnerability in its rename functionality that permits unauthenticated users to execute arbitrary code on the server. An attacker can exploit this by renaming uploaded files with a .png extension to use a .php extension instead, allowing the execution of malicious PHP code. This flaw was fixed in version 4.2.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.