QID 731039

Date Published: 2023-12-21

QID 731039: WordPress Plugin Simplepress Remote Code Execution (RCE) Vulnerability

Simple:Press is an all-in-one, feature-rich forum plugin designed to seamlessly integrate with your WordPress site.

CVE-2020-36706 : A broken access control issue in the plugin, which could lead to unauthenticated arbitrary file and RCE.

Affected Versions:
WordPress Simplepress plugin versions prior to 6.6.1

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Simplepress Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability could lead to unauthenticated arbitrary file and RCE

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to WP Simplepress version 6.6.1 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731039

    Software Advisories
    Advisory ID Software Component Link
    simplepress URL Logo wordpress.org/plugins/simplepress/#developers