CVE-2020-24186 CRITICAL

CVE-2020-24186

Vendor N/A
Product n/a
Published August 24, 2020
Last update August 4, 2024

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N

What the vulnerability does

01Description

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Key dates

02Disclosure timeline

August 24, 2020 CVE published
August 4, 2024 Record updated