This Metasploit module exploits an arbitrary file upload in the WordPress wpDiscuz plugin versions from 7.0.0 through 7.0.4. This flaw gave unauthenticated attackers the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable server.
fab2eeb88db6a1f9b11eed6c490a6ca021dd6f8237a47b405d41bd041a36af45
WordPress wpDiscuz plugin version 7.0.4 unauthenticated remote code execution exploit.
aa63e68f2bfdeedda7921d223b7b89c35603743db979d8834247d72fc6863c1e
WordPress wpDiscuz plugin version 7.0.4 remote shell upload exploit.
8fa69935470b723c80f2977560b14f53d9cb4f4b6055bb73e01b783fd7f62aad