WordPress Plugin Vulnerabilities

Comments - wpDiscuz 7.0.0 - 7.0.4 - Unauthenticated Arbitrary File Upload

Description

This flaw gave unauthenticated attackers the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable site’s server.

Proof of Concept

Affects Plugins

Fixed in 7.0.5

References

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2020-07-28 (about 5 years ago)
Added
2020-07-28 (about 5 years ago)
Last Updated
2020-08-25 (about 5 years ago)

Other