CVE-2020-36847 Details
Description
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
A remote code execution vulnerability exists in the Simple File List WordPress plugin, affecting versions prior to 4.2.3. The issue arises from an unauthenticated arbitrary file upload feature, which allows attackers to upload PHP files disguised as PNG images. Once uploaded, these files can be renamed to use a .php extension and executed on the server.
Users are advised to update the Simple File List WordPress plugin to version 4.2.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/365da9c5-a8d0-45f6-863c-1b1926ffd574/ | CISA-ADP | ExploitThird Party Advisory |
| https://packetstormsecurity.com/files/160221/ | [email protected] | Exploit |
| https://plugins.trac.wordpress.org/changeset/2286920/simple-file-list | [email protected] | Patch |
| https://wpscan.com/vulnerability/365da9c5-a8d0-45f6-863c-1b1926ffd574/ | [email protected] | ExploitThird Party Advisory |
| https://www.cybersecurity-help.cz/vdb/SB2020042711 | [email protected] | Third Party Advisory |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/9eb835fd-6ebf-4162-856c-0366b663a07e?source=cve | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| simplefilelist simple file list | < 4.2.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | Initial Analysis | [email protected] |
| Jul 14, 2025 | CVE Modified | CISA-ADP |
| Jul 12, 2025 | New CVE Received | [email protected] |