Netskope Threat Labs

SERVER-WEBAPP WordPress wpDiscuz plugin arbitrary PHP file upload attempt

IPS-NPA

1 SID: 63143

Detects an attempt to exploit CVE-2020-24186, an arbitrary file upload flaw that can plant webshells on the server in WordPress wpDiscuz plugin arbitrary PHP. The flaw saw mass exploitation of sites running the vulnerable plugin to upload webshells.