CVE-2025-34085: WordPress Simple File List Plugin < 4.2.3 Unauthenticated Remote Code Execution
Published Jul 9, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36847.
Affected Software
1 affected component
WordPress Simple File List<4.2.3
Event History
Jul 9, 2025
CVE Published
via MITRE·12:48 AM
Rejected
via MITRE·12:48 AM
Data Sourced
via NVD·01:15 AM
Description
Jul 16, 2025
Rejected
via MITRE·03:48 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-34085?
CVE-2025-34085 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-34085?
To mitigate CVE-2025-34085, upgrade the WordPress Simple File List plugin to version 4.2.3 or later.
3
What types of attacks can be executed via CVE-2025-34085?
Attackers can exploit CVE-2025-34085 to perform unauthenticated remote code execution on vulnerable systems.
4
Which versions of the WordPress Simple File List plugin are affected by CVE-2025-34085?
All versions of the WordPress Simple File List plugin prior to version 4.2.3 are affected by CVE-2025-34085.
5
Is authentication required to exploit CVE-2025-34085?
No, CVE-2025-34085 can be exploited by unauthenticated remote attackers.