S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 6, 2026

CVE-2016-15043 Scanner

CVE-2016-15043 Scanner - Unrestricted File Upload vulnerability in WP Mobile Detector

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-15043
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Mobile Detectorby Websitez.com, LLC
0
Updated Aug 22, 2026View on NVD →
Detail

The "WP Mobile Detector" plugin is widely used by WordPress administrators aiming to optimize their websites for mobile device visitors. By detecting user agents, it tailors resolutions and formats to deliver a more user-friendly experience. Its primary customers include bloggers, small business sites, and tech enthusiasts who prioritize mobile accessibility. Given the vast user base of WordPress, this plugin is a go-to choice for those without intensive programming capabilities. The plugin's ease of deployment and compatibility with various themes further boost its popularity. However, the increasing reliance on such plugins underscores the need for robust security mechanisms.

The identified vulnerability in the "WP Mobile Detector" involves a failure to validate file types during uploads, manifested in the "resize.php" script. This oversight can lead to the unrestricted upload of potentially harmful files, allowing unauthorized access. Such vulnerabilities are common when plugins do not enforce strict security protocols. For attackers, exploiting this flaw can offer a gateway for malicious initiatives. As this issue affects versions up to 3.5, patching is imperative to protect systems. Remaining vigilant against such threats ensures both user data and site integrity.

Technical analysis of the "WP Mobile Detector" plugin reveals that the primary vulnerability lies within the "resize.php" script. It inadequately checks the legitimacy of file types, especially when handling input via the "src" parameter. Coupled with an unauthenticated upload mechanism, it provides a ripe opportunity for manipulation. Attackers can manipulate the upload mechanism to place malicious scripts, subsequently achieving remote code execution. This unfiltered access can jeopardize web server configurations, exposing sensitive data and functionality. Affected installations belong to those running versions up to 3.5 without subsequent patches, leaving them open to this flaw.

Exploitation of the unrestricted file upload vulnerability in the "WP Mobile Detector" poses several risks. The primary threat is remote code execution, leading to full server compromise. Attackers can intrusively upload scripts to alter or access sensitive files. This compromise in security can further escalate to defacement, sensitive data leaks, or unauthorized access to backend systems. Website integrity can be critically undermined, eroding user trust and enhancing the risk of further exploit attempts. With systems exposed, user data confidentiality and availability are jeopardized when left unpatched.

REFERENCES

Solution Advice
  • Update to the latest version of WP Mobile Detector plugin to ensure security patches are applied.
  • Betting configure file upload directories with strict permissions to limit execution capability.
  • Implement server-side validation for file types, ensuring only legitimate formats are processed.
  • Consider utilizing web application firewalls to detect and block malicious uploads.
  • Regularly audit and monitor logs for unusual activities indicating upload attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-15043 Scanner - Unrestricted File Upload vulnerability in WP Mobile Detector | S4E