CVE-2020-24186
Summary
| CVE | CVE-2020-24186 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-24 14:15:00 UTC |
| Updated | 2022-01-01 18:46:00 UTC |
| Description | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress wpDiscuz 7.0.4 Shell Upload ≈ Packet Storm | MISC | packetstormsecurity.com | |
| WordPress wpDiscuz 7.0.4 Shell Upload ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Critical Arbitrary File Upload Vulnerability Patched in wpDiscuz Plugin | MISC | www.wordfence.com | Exploit, Third Party Advisory |
| WordPress wpDiscuz 7.0.4 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730731 WordPress Plugin WpDiscuz Remote Code Execution (RCE) Vulnerability