CVE-2020-24186 is a remote code execution vulnerability in the gVectors wpDiscuz plugin versions 7.0 through 7.0.4 for WordPress. The vulnerability arises from improper validation in the wmuUploadFiles AJAX action, which allows unauthenticated users to upload arbitrary files, including executable PHP files. This enables attackers to upload and execute malicious code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2020-24186 affecting the WordPress wpDiscuz plugin 7.0.4. The repository contains only three files: an MIT LICENSE, a brief README identifying the target vulnerability, and the main exploit script poc.py. The script is the sole functional component and serves as the entry point. The exploit workflow is straightforward: it accepts a base target URL (-u) and a plugin/page path (-p), performs an HTTP GET to the supplied page, and extracts two values from the HTML/JavaScript response using regex: wmuSecurity and wc_post_id. It then crafts a multipart/form-data POST request to /wp-admin/admin-ajax.php with action=wmuUploadFiles and uploads a randomized .php file containing a minimal PHP webshell disguised with a GIF header. After upload, it parses the returned JSON-like response to recover the uploaded file URL, prints the webshell location, and opens an interactive pseudo-shell. Commands entered by the operator are sent as GET requests using the cmd parameter, and command output is displayed after stripping the GIF marker. Main exploit capability: unauthenticated or weakly protected remote code execution via arbitrary file upload leading to persistent webshell placement. This is not merely a detector; it actively weaponizes the vulnerability by planting a server-side shell. The payload is basic and hardcoded rather than modular, so the maturity is best classified as OPERATIONAL rather than framework-grade or weaponized.
This repository contains an exploit for CVE-2020-24186, targeting the WP-Discuz WordPress plugin version 7.0.4. The exploit consists of two files: 'poc.sh', a Bash script that automates the exploitation process, and 'shell.php', a minimal PHP web shell payload. The script takes a list of target URLs, checks if each is running the vulnerable plugin version, extracts necessary tokens and post IDs from the site's content, and attempts to upload the PHP shell via a crafted POST request to the 'admin-ajax.php' endpoint. If successful, the shell can be accessed via the returned URL, allowing arbitrary command execution on the server. The exploit is operational and automates both detection and exploitation, requiring only a list of target sites as input. The endpoints targeted are typical of WordPress installations with the WP-Discuz plugin.
This repository contains a single Metasploit module targeting the WordPress wpDiscuz plugin (versions 7.0.0 to 7.0.4) for an unauthenticated arbitrary file upload vulnerability (CVE-2020-24186). The exploit works by sending a specially crafted multipart/form-data POST request to the /wp-admin/admin-ajax.php endpoint, abusing the plugin's file upload functionality to upload a PHP payload. After successful upload, the module locates the uploaded file in the /wp-content/uploads/<year>/<month>/ directory and triggers it to achieve remote code execution. The module requires the attacker to specify a valid blog post path (BLOGPATH) and leverages the 'wmuSecurity' nonce extracted from the blog page. The default payload is a PHP Meterpreter reverse shell, but any Metasploit-compatible PHP payload can be used. The exploit is operational and leaves artifacts (the uploaded PHP file) on the target server. The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository contains a Python exploit script (CVE-2020-24186.py) targeting the WordPress CVE-2020-24186 vulnerability, which allows unauthenticated file upload via the admin-ajax.php endpoint. The script automates the exploitation process by first retrieving a required security token from a blog page, then uploading a camouflaged PHP webshell (disguised as a GIF image) to the server. Once uploaded, the script can either provide an interactive shell (executing commands via the webshell's 'cmd' parameter) or trigger a reverse shell back to the attacker's machine using various methods (bash, nc, python). The exploit supports proxying requests for traffic inspection or evasion. The repository includes a README with detailed usage instructions and operational modes. The main code file is well-structured, modular, and leverages the 'requests' and 'pwntools' libraries for HTTP interaction and reverse shell handling. The exploit is operational and provides real post-exploitation access if the target is vulnerable.
This repository contains a working exploit for CVE-2020-24186, a remote code execution vulnerability in the gVectors wpDiscuz WordPress plugin (versions 7.0 through 7.0.4). The exploit is implemented in Python (wpDiscuz_RemoteCodeExec.py) and automates the process of uploading a malicious PHP webshell to a vulnerable WordPress instance. It does so by first retrieving necessary CSRF tokens and post IDs from a specified blog post, then crafting a multipart/form-data POST request to the /wp-admin/admin-ajax.php endpoint using the vulnerable 'wmuUploadFiles' AJAX action. The uploaded file is a PHP webshell that allows the attacker to execute arbitrary system commands via HTTP requests. The exploit is operational and provides an interactive shell for command execution. The repository also includes a README.md with usage instructions and references. No detection scripts or fake code are present; the exploit is functional and targets real-world deployments of the vulnerable plugin.
This repository contains an exploit for CVE-2020-24186, a remote code execution vulnerability in the wpDiscuz WordPress plugin version 7.0.4. The exploit is implemented in a single Python script (exploit.py) and is accompanied by a README.md with usage instructions. The script automates the process of exploiting the file upload vulnerability to upload a PHP reverse shell (based on pentestmonkey's php-reverse-shell) to the target WordPress site. The attacker specifies the target URL, a post path, and their own IP and port for the reverse shell connection. The script retrieves necessary CSRF tokens, generates a random filename for the shell, and crafts a multipart/form-data POST request to upload the shell via the /wp-admin/admin-ajax.php endpoint. If successful, the attacker is instructed to trigger the shell and receive a remote shell connection. The repository is operational and provides a working exploit with a real payload, targeting a specific plugin and version. No detection or fake code is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.