module
WordPress wpDiscuz Unauthenticated File Upload Vulnerability
Disclosed | Created |
---|---|
2020-02-21 | 2021-06-26 |
Disclosed
2020-02-21
Created
2021-06-26
Description
This module exploits an arbitrary file upload in the WordPress wpDiscuz plugin
versions >= `7.0.0` and to upload arbitrary files, including PHP files, and achieve remote code execution on a
vulnerable site’s server.
versions >= `7.0.0` and to upload arbitrary files, including PHP files, and achieve remote code execution on a
vulnerable site’s server.
Authors
Chloe Chamberland
Hoa Nguyen - SunCSR
Hoa Nguyen - SunCSR
Platform
PHP
Architectures
php
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.