Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution

2021-06-06 00:00
Chloe Chamberland

Strategic Overview

Status
Patched in 7.0.5
Affected PluginComments – wpDiscuz
Affected Version7.0 – 7.0.4
CVSS9.8Critical
CVECVE-2020-24186
View all Comments – wpDiscuz vulnerabilities

Vulnerability Overview

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Technical Analysis

REMEDIATION: Update to version 7.0.5, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C