vendor:
Simple Fields WordPress Plugin
by:
Graeme Robinson
7.5
CVSS
HIGH
Local File Inclusion/Remote File Inclusion/Remote Code Execution
98
CWE
Product Name: Simple Fields WordPress Plugin
Affected Version From: 0.2
Affected Version To: 0.3.5
Patch Exists: YES
Related CWE: N/A
CPE: a:simple_fields:simple_fields
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.04.4 + PHP 5.3.0
2018
Simple Fields 0.2 – 0.3.5 LFI/RFI/RCE
Versions 0.2 to 0.3.5 of the Simple Fields WordPress plugin are vulnerable to local file inclusion if running on PHP <5.3.4. This can even lead to remote code execution, for example by injecting php code into the apache logs or if allow_url_include is turned on in php.ini. The vulnerability was fixed (commented out) in version 0.3.6 on 2011-02-03.
Mitigation:
Upgrade PHP to 5.3.4+, Update Simple Fields to 0.3.6+, Stop using Simple Fields because it is no longer supported