← back
CVE-2016-15043

WP Mobile Detector <= 3.5 - Arbitrary File Upload

CVSS 9.8 CRITICALEPSS 10.0%CWE-434
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 10.0%KEV nãoPoC Nuclei simMetasploit simPatch
Lifecycle
31 May 2016Metasploit module available
19 Jul 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →