CVE-2020-24186: Malicious File Upload
Published Aug 24, 2020
·Updated
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
Affected Software
1 affected component
gVectors Wpdiscuz Wordpress>=7.0<=7.0.4
Event History
Aug 24, 2020
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-24186.
2
What is the severity of CVE-2020-24186?
The severity of CVE-2020-24186 is critical.
3
What is the affected software?
The affected software is the gVectors wpDiscuz plugin version 7.0 through 7.0.4 for WordPress.
4
What can an unauthenticated user do with CVE-2020-24186?
An unauthenticated user can upload any type of file, including PHP files, via the wmuUploadFiles AJAX action.
5
Are there any known fixes for CVE-2020-24186?
There are no known fixes for CVE-2020-24186 at the moment. It is recommended to disable or remove the gVectors wpDiscuz plugin until a patch is available.