E16-e1x01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
42
Year:
2016
Description
This strike exploits an unauthenticated file-upload vulnerability in WordPress Mobile-Detector plugin.
The vulnerability is due to insufficient validation of user input
A remote file upload vulnerability exists in Wordpress Download Manager Plugin versions prior to 2.7.5.
This vulnerability allows an unauthenticated attacker to upload a file to the web server and could facilitate
remote code execution with the privileges of the account running the web server application.
References
https://wordpress.org/plugins/wp-mobile-detector/changelog/