Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-24186-wpDiscuz-7.0.4-RCE — wpDiscuz 7.0.4 Remote Code Execution | Kitploit
Tools/GitHubGitHub/hev0x/cve-2020-24186-wpdiscuz-7.0.4-rce
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubhev0x/cve-2020-24186-wpdiscuz-7.0.4-rce

CVE-2020-24186-wpDiscuz-7.0.4-RCE

wpDiscuz 7.0.4 Remote Code Execution

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
1925 years agoNot yet reviewed

POC CVE-2020-24186-wpDiscuz-7.0.4-RCE

WordPress wpDiscuz 7.0.4 Remote Code Execution

  • A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

Exploit Usage

Commands:

  • Windows/Linux: $ sudo python3 wpDiscuz_RemoteCodeExec.py -u <Base_Host> -p <BlogPost_URL>

  • References:

    https://www.exploit-db.com/exploits/49967

    https://packetstormsecurity.com/files/163012/WordPress-wpDiscuz-7.0.4-Remote-Code-Execution.html

    https://nvd.nist.gov/vuln/detail/CVE-2020-24186

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24186

Download Tool