PT-2026-41550 · WordPress · Simple-Fields
Published
2026-05-17
·
Updated
2026-05-17
·
CVE-2018-25324
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Fields versions 0.2 through 0.3.5
Description
A local file inclusion issue allows unauthenticated attackers to read arbitrary files, such as /etc/passwd, by injecting null bytes into the
wp abspath parameter within the 'simple fields.php' file. This occurs on PHP versions prior to 5.3.4. Additionally, if the allow url include setting is enabled, attackers can inject PHP code into Apache logs to achieve remote code execution.Recommendations
Update Simple Fields to a version later than 0.3.5.
As a temporary mitigation, restrict access to the 'simple fields.php' file or avoid using the
wp abspath parameter until the update is applied.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple-Fields