S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-24186 Scanner

CVE-2020-24186 scanner - Remote Code Execution (RCE) vulnerability in gVectors wpDiscuz plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-24186
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

gVectors wpDiscuz is a WordPress plugin that enables website owners to add comments to their web pages. The plugin is renowned for its flexibility and versatility, and it allows users to customize the commenting system according to their needs. For example, the plugin offers features such as comment sorting and filtering, comment voting, and integration with social media platforms. It also allows visitors to post comments with emojis, images, and videos.

However, the plugin has recently been found to contain a Remote Code Execution vulnerability, designated as CVE-2020-24186. This vulnerability allows any unauthenticated user to upload files of any type, including PHP files, via the wmuUploadFiles AJAX action. This could potentially put the website owner's whole system at risk as an attacker could upload a malicious PHP file to execute arbitrary code on the server.

When this vulnerability is exploited, it can potentially allow an attacker to hijack the website’s files and steal sensitive data or take control of the server altogether. This could lead to the website being defaced, vandalized, or held to ransom. Such attacks are a real and present danger to any website, which needs to protect its digital assets.

In closing, it is essential for website owners to stay informed about any security vulnerabilities in their digital assets, such as gVectors wpDiscuz. s4e.io proactively scans these assets for vulnerabilities and provides users with a detailed report on any issues found. By subscribing to s4e.io, users can stay up to date on the latest vulnerabilities that threaten their digital assets and can take quick and effective corrective action. By staying ahead of the curve, it is possible to reduce the risk of cyberattacks and protect against devastating consequences.

 

REFERENCES

Solution Advice

Various precautions can be taken to protect against this vulnerability, including:

  • Updating to version 7.0.5 or later of gVectors wpDiscuz plugin as this version fixes the vulnerability.
  • Removing the plugin if it is not in use, especially if it is out of date.
  • Providing access to server files and directories to only trusted users.
  • Setting proper file permissions to uploaded files and directories.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-24186 scanner - Remote Code Execution (RCE) vulnerability in gVectors wpDiscuz plugin for WordPress | S4E