Critical vulnerability in the WordPress plugin wpDiscuz, which has 80,000 installations

In the WordPress plugin wpDiscuz, which is installed on more than 80,000 sites, identified a dangerous vulnerability that allows unauthorized file uploads to the server. This includes the ability to upload PHP files and execute arbitrary code on the server. The affected versions range from 7.0.0 to 7.0.4 inclusive. The vulnerability has been fixed in version 7.0.5.

The wpDiscuz plugin allows for AJAX-based dynamic comment submission without reloading the page. The vulnerability is due to a flaw in the file type validation code used for attaching images to comments. The function for determining MIME type from content was called to restrict arbitrary file uploads, but it could be easily bypassed to upload PHP files. File extension restrictions were not enforced. For example, a file named myphpfile.php could be uploaded by initially specifying the sequence 89 50 4E 47 0D 0A 1A 0A, which identifies PNG images, and then placing a block of PHP code with ‘<?php’.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster