June 3, 2016
Attackers have been using a newly discovered zero-day in the WP Mobile Detector plugin to upload backdoor scripts on WordPress sites and are currently employing it to upload adult-themed SEO spam on affected websites.
WP is a favorite of hackers and seems to stay in the news. The team at Plugin Vulnerabilities has discovered that the new Zero Day plugin features an arbitrary file upload vulnerability in the “/wp-content/plugins/wp-mobile-detector/resize.php” file.
Using this vulnerability, attackers can upload PHP-based backdoors on WordPress sites, something that should have been almost impossible in 2016, after almost two decades of PHP coding and basic lessons in file upload security.
