CVE-2020-36847 | Simple-File-List Plugin up to 4.2.2 on WordPress PHP Extension rename unrestricted upload (EUVD-2020-30797)
A vulnerability, which was classified as critical, was found in Simple-File-List Plugin up to 4.2.2 on WordPress. This affects the function rename of the component PHP Extension Handler. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2020-36847. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.