WordPress WPTouch Mobile plug-in Arbitrary File Upload Vulnerability
Released on: 2014-09-03
Updated on: 2014-09-05
Affected Systems:
WordPress WPTouch Mobile 3.4.6
Description:
--------------------------------------------------------------------------------
The WordPress WPTouch Mobile plug-in automatically enables simple Mobile themes for Mobile users on the WordPress website.
WordPress WPTouch Mobile plug-in 3.4.6 does not correctly verify MIME-type files when uploading icons and images. This allows you to upload and execute any PHP code.
<* Source: k4L0ng666
Link: http://secunia.com/advisories/59809/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/plugins/wptouch/changelog/
This article permanently updates the link address: