Wordpress Mobile Detector Plugin Remote File Upload

Strike ID:
E16-e1x01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
42
Year:
2016

Description

This strike exploits an unauthenticated file-upload vulnerability in WordPress Mobile-Detector plugin. The vulnerability is due to insufficient validation of user input A remote file upload vulnerability exists in Wordpress Download Manager Plugin versions prior to 2.7.5. This vulnerability allows an unauthenticated attacker to upload a file to the web server and could facilitate remote code execution with the privileges of the account running the web server application.

References