A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
PoC: CVE-2020-24186-WordPress-wpDiscuz-7.0.4-RCE
wpDiscuz 7.0.4 Remote Code Execution
PoC: CVE-2020-24186-exploit
CVE-2020-24186的攻击脚本
[POC] GHSA-3mgp-fx93-9xv5 — CVE-2020-24186
Exploit para RCE (Remote Code Exec) CVE de plugin vulnerable en Wordpress WP-Discuz en versión 7.0.4
PoC: CVE-2020-24186
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free