QID 730731
Date Published: 2023-02-22
QID 730731: WordPress Plugin WpDiscuz Remote Code Execution (RCE) Vulnerability
WpDiscuz plugin changes your website commenting experience and provides you with new user engagement features.
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
Affected Versions:
WpDiscuz plugin versions from 7.0.0 prior to 7.0.5
QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the WpDiscuz plugin.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to upload malicious file and execute code on the target system.
Solution
Customers are advised to install WpDiscuz 7.0.5 or later version to remediate this vulnerability.
Vendor References
- WpDiscuz Release Notes -
wordpress.org/plugins/wpdiscuz/#developers
CVEs related to QID 730731
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WpDiscuz Release Notes |
|