Simple Fields 0.2 through 0.3.5 WordPress Plugin contains...
Moderate severity
Unreviewed
Published
May 17, 2026
to the GitHub Advisory Database
•
Updated May 17, 2026
Description
Published by the National Vulnerability Database
May 17, 2026
Published to the GitHub Advisory Database
May 17, 2026
Last updated
May 17, 2026
Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_fields.php to include files like /etc/passwd or inject PHP code into Apache logs for remote code execution when allow_url_include is enabled.
References