Critical vulnerability in the WordPress plugin wpDiscuz, which has 80,000 installations
A dangerous vulnerability has been discovered in the WordPress plugin wpDiscuz, which is installed on over 80,000 sites. This flaw allows anyone to upload any file to the server without authentication, including PHP files, thereby executing their code on the server. Versions affected are from 7.0.0 to 7.0.4 inclusive. The vulnerability has been fixed in release 7.0.5. The wpDiscuz plugin allows the use of AJAX for […]
