vendor:
WP Mobile Detector
by:
Aaditya Purani
8,8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: WP Mobile Detector
Affected Version From: 3.5
Affected Version To: 3.5
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wp-mobile-detector
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0 Sana / Windows 10
2015
WP Mobile Detector <=3.5 Arbitrary File upload
This Vulnerability has been disclosed to public yesterday about WP Mobile Detector Arbitrary File upload for version <=3.5 in which attacker can upload malicious PHP Files (Shell) into the Website. Over 10,000 users are affected, Vendor has released a Patch in their version 3.6 & 3.7 at https://wordpress.org/plugins/wp-mobile-detector/changelog/.
Mitigation:
Vendor has released a Patch in their version 3.6 & 3.7 at https://wordpress.org/plugins/wp-mobile-detector/changelog/.