CVE-2016-15043Active Exploitation(wp_mobile_detector_project / wp_mobile_detector)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for wp_mobile_detector_project wp_mobile_detector systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wp_mobile_detector

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
wp_mobile_detector

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Active Exploitation · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Active Exploitation

    🚨 CVE-2016-15043: WP Mobile Detector <= 3.5 - Arbi... Unauthenticated RCE via resize.php in WP Mobile Detector lets attackers upload shells with zero resistance - actively e... https://zerodaysignal.com/vulnerability/CVE-2016-15043 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2016‑15043 is an unauthenticated remote code execution flaw in WP Mobile Detector ≤3.5, allowing attackers to upload shells; the author reports it is actively exploited in the wild.

    0000148
    131 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwp_mobile_detector_projectwp_mobile_detector-wordpress-

Explore more