QID 731039
Date Published: 2023-12-21
QID 731039: WordPress Plugin Simplepress Remote Code Execution (RCE) Vulnerability
Simple:Press is an all-in-one, feature-rich forum plugin designed to seamlessly integrate with your WordPress site.
CVE-2020-36706 : A broken access control issue in the plugin, which could lead to unauthenticated arbitrary file and RCE.
Affected Versions:
WordPress Simplepress plugin versions prior to 6.6.1
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Simplepress Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability could lead to unauthenticated arbitrary file and RCE
Solution
Customers are advised to upgrade to WP Simplepress version 6.6.1 and later to remediate this vulnerability.
Vendor References
- WP Simplepress Plugin Release Notes -
wordpress.org/plugins/simplepress/#developers
CVEs related to QID 731039
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| simplepress |
|