CVE-2025-34085
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
09/07/2025
Last modified:
16/07/2025
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36847.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL
References to Advisories, Solutions, and Tools
- https://packetstorm.news/files/id/160221
- https://plugins.trac.wordpress.org/changeset/2286920/simple-file-list
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_simple_file_list_rce.rb
- https://simplefilelist.com/
- https://vulncheck.com/advisories/wordpress-simple-file-list-plugin-rce
- https://web.archive.org/web/20220426044003/https://wpscan.com/vulnerability/10192/
- https://wordpress.org/plugins/simple-file-list/
- https://www.cybersecurity-help.cz/vdb/SB2020042711
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-file-list/simple-file-list-423-remote-code-execution



