CRITICAL

CVE-2020-24186

CVSS v3

10

CRITICAL

EPSS Score

94.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Technical details

Published
8/24/2020

Frequently asked questions

What is CVE-2020-24186?

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Is CVE-2020-24186 actively exploited?

Active exploitation of CVE-2020-24186 has not been confirmed. The EPSS score is 94.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-24186?

CVE-2020-24186 has a CVSS v3 base score of 10 (CRITICAL severity).

Is CVE-2020-24186 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.