PT-2020-15645 · Gvectors · Wpdiscuz

Published

2020-08-24

·

Updated

2025-12-23

·

CVE-2020-24186

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gVectors wpDiscuz plugin versions 7.0 through 7.0.4
Description A Remote Code Execution issue exists, allowing unauthenticated users to upload any type of file, including PHP files, via the wmuUploadFiles AJAX action.
Recommendations For versions 7.0 through 7.0.4, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the wmuUploadFiles AJAX action to prevent unauthenticated file uploads.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24186

Affected Products

Wpdiscuz