vendor:
wpDiscuz
by:
Chloe Chamberland & Juampa Rodríguez
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: wpDiscuz
Affected Version From: 7.0.4
Affected Version To: 7.0.4
Patch Exists: YES
Related CWE: CVE-2020-24186
CPE: a:gvectors:wpdiscuz:7.0.4
Metasploit:
N/A
Platforms Tested: Ubuntu / WordPress 5.6.2
2021
WordPress Plugin wpDiscuz 7.0.4 – Arbitrary File Upload (Unauthenticated)
This exploit allows an unauthenticated attacker to upload a webshell to the vulnerable Wordpress Plugin wpDiscuz 7.0.4. The attacker can then use the webshell to execute arbitrary commands on the server. This exploit was discovered by Chloe Chamberland and further developed by Juampa Rodríguez aka UnD3sc0n0c1d0.
Mitigation:
The user should update the plugin to the latest version and ensure that all plugins are up to date.