Eemitch Simple File List vulnerabilities
2 known vulnerabilities affecting eemitch/simple_file_list.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2020-36847CRITICALCVSS 9.8PoCfixed in 4.2.32025-07-12
CVE-2020-36847 [CRITICAL] CWE-434 CVE-2020-36847: The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to,
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
cvelistv5nvd
CVE-2022-1119HIGHCVSS 7.5ExploitedPoC≤ 3.2.72022-04-19
CVE-2022-1119 [HIGH] CWE-22 CVE-2022-1119: The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parame
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.
cvelistv5nvd