U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-34085

Change History

CVE Modified by VulnCheck 7/16/2025 12:15:26 PM

Action Type Old Value New Value
Changed Description
An unrestricted file upload vulnerability in the WordPress Simple File List plugin prior to version 4.2.3 allows unauthenticated remote attackers to achieve remote code execution. The plugin's upload endpoint (ee-upload-engine.php) restricts file uploads based on extension, but lacks proper validation after file renaming. An attacker can first upload a PHP payload disguised as a .png file, then use the plugin’s ee-file-engine.php rename functionality to change the extension to .php. This bypasses upload restrictions and results in the uploaded payload being executable on the server.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36847.
Removed CVSS V4.0
VulnCheck: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

								
						
Removed CWE
VulnCheck: CWE-306

								
						
Removed CWE
VulnCheck: CWE-434

								
						
Removed Reference
VulnCheck: https://packetstorm.news/files/id/160221

								
						
Removed Reference
VulnCheck: https://plugins.trac.wordpress.org/changeset/2286920/simple-file-list

								
						
Removed Reference
VulnCheck: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_simple_file_list_rce.rb

								
						
Removed Reference
VulnCheck: https://simplefilelist.com/

								
						
Removed Reference
VulnCheck: https://vulncheck.com/advisories/wordpress-simple-file-list-plugin-rce

								
						
Removed Reference
VulnCheck: https://web.archive.org/web/20220426044003/https://wpscan.com/vulnerability/10192/

								
						
Removed Reference
VulnCheck: https://wordpress.org/plugins/simple-file-list/

								
						
Removed Reference
VulnCheck: https://www.cybersecurity-help.cz/vdb/SB2020042711

								
						
Removed Reference
VulnCheck: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-file-list/simple-file-list-423-remote-code-execution

								
						

CVE Rejected by VulnCheck 7/16/2025 12:15:26 PM

Action Type Old Value New Value