PoC Index

CVE-2020-24186

CRITICAL 10.0EPSS 94.6%

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

CVSS v3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
94.62% chance of exploitation in the next 30 days, 100th percentile
Nuclei
critical · CWE-434
Published
2020-08-24
Updated
2024-08-04

Proof-of-concept exploits (12)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (2)

References

Related