漏洞描述 WordPress Simple File List 插件是一款用于管理文件列表的插件,广泛应用于 WordPress 网站中。该插件的 /wp-content/plugins/simple-file-list/ee-upload-engine.php 文件存在代码执行漏洞(CVE-2025-34085)。攻击者可以通过该漏洞上传恶意文件并执行任意代码,从而完全控制受影响的 WordPress 网站。
相关漏洞推荐 CVE-2022-1119: WordPress Simple File List <3.2.8 - Local File Inclusion POC 2025-09-01 | WordPress Simple File List WordPress Simple File List before 3.2.8 is vulnerable to local file inclusion via the eeFile paramet... CVE-2022-1119: WordPress Simple File List <3.2.8 - Local File Inclusion POC 2025-08-01 | WordPress Simple File List WordPress Simple File List before 3.2.8 is vulnerable to local file inclusion via the eeFile paramet... CVE-2025-34085: WordPress Simple File List <=4.2.2 - Remote Code Execution POC 2025-08-01 | WordPress Simple File List An unrestricted file upload vulnerability in the WordPress Simple File List plugin before version 4.... Wordpress Plugin Depicter /wp-admin/admin-ajax.php depicter-lead-list SQL 注入漏洞(CVE-2025-2011) 无POC 2025-09-19 | Wordpress WordPress插件Depicter的滑块和弹出窗口构建器在包括3.6.1版本在内的所有版本中,由于用户提供的参数缺乏足够的转义处理和现有SQL查询的预处理不足,存在通用的SQL注入漏洞。该漏洞可以... Wordpress Plugin Eventin /wp-admin/admin-ajax.php proxy_image 文件读取漏洞(CVE-2025-3419) 无POC 2025-09-19 | Wordpress Event Manager, Events Calendar, Tickets, Registrations – Eventin 是一个用于 WordPress 的插件。该漏洞存在于其 proxy_i...