CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- August 13, 2020
- Published Date
- August 24, 2020
- Last Updated
- August 04, 2024
- Vendor
- n/a
- Product
- n/a
- Description
- A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
- Tags
- Score
- 93.86% (Percentile: 99.86%) as of 2025-05-12
- Exploited in the Wild
- Yes (2020-07-28 14:15:03 UTC) Source
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Score
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
Wordfence | 2020-07-28 14:15:03 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_wpdiscuz_unauthenticated_file_upload.rb | 2025-04-29 11:01:29 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-24186.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
wp_wpdiscuz_unauthenticated_file_upload
Type: metasploit • Created: Unknown
GazettEl/CVE-2020-24186
Type: github • Created: 2025-03-05 04:10:06 UTC • Stars: 0
substing/CVE-2020-24186_reverse_shell_upload
Type: github • Created: 2023-12-21 23:23:43 UTC • Stars: 13
Sakura-501/CVE-2020-24186-exploit
Type: github • Created: 2022-04-05 08:31:56 UTC • Stars: 3
meicookies/CVE-2020-24186
Type: github • Created: 2021-08-13 11:32:47 UTC • Stars: 0
hev0x/CVE-2020-24186-wpDiscuz-7.0.4-RCE
Type: github • Created: 2021-06-13 23:10:19 UTC • Stars: 18
Timeline
-
Added to KEVIntel
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei
-
Detected by Metasploit