Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution
2021-06-06 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 7.0.5
Affected PluginComments – wpDiscuz
Affected Version
7.0 – 7.0.4CVSS9.8Critical
CVE
CVE-2020-24186Vulnerability Overview
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
Technical Analysis
REMEDIATION: Update to version 7.0.5, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C