Exploitation for CVE-2020-36847 (Remote Code Execution in Wordpress Simple File List plugin)
Copy link to “Exploitation for CVE-2020-36847 (Remote Code Execution in Wordpress Simple File List plugin)”We’ve added an exclusive exploit for CVE-2020-36847 (WordPress Simple File List - Unauthenticated RCE) into Sniper, so you can move from suspicion to proof of rce in a controlled, ethical way.
Why it matters
CVE-2020-36847 is a critical, unauthenticated Remote Code Execution vulnerability in the Simple File List plugin for WordPress. Versions up to and including 4.2.2 let an attacker upload a php payload disguised as an image, then use the plugin’s rename function to change the extension to .php and run it on the server. The result is full arbitrary code execution with no login required, a fast path to site takeover, database access, credential theft, and lateral movement if the host can reach internal services. Updating to 4.2.3 or later fixes the issue.
How to use
Validate in Sniper → capture RCE evidence safely → patch the plugin (4.2.3+) → re-run Sniper to confirm remediation and rule out other exposed sites using the same plugin.





.png&w=1536&q=100)





