peter bassill · operator
$ cve CVE-2020-24186 JSON

CVE-2020-24186 EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 94.6% (pctl 100)

Patch early

A public exploit exists.

Description

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS94.62% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2020-08-24
Last modified2026-06-17

Affected (1)

VendorProduct
gvectorswpdiscuz

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD