PT-2026-41550 · WordPress · Simple-Fields

Published

2026-05-17

·

Updated

2026-05-17

·

CVE-2018-25324

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Fields versions 0.2 through 0.3.5
Description A local file inclusion issue allows unauthenticated attackers to read arbitrary files, such as /etc/passwd, by injecting null bytes into the wp abspath parameter within the 'simple fields.php' file. This occurs on PHP versions prior to 5.3.4. Additionally, if the allow url include setting is enabled, attackers can inject PHP code into Apache logs to achieve remote code execution.
Recommendations Update Simple Fields to a version later than 0.3.5. As a temporary mitigation, restrict access to the 'simple fields.php' file or avoid using the wp abspath parameter until the update is applied.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2018-25324

Affected Products

Simple-Fields