Description
WordPress Plugin WPtouch is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently e.g. upload and execute arbitrary PHP code; this could lead to total compromise of the website. WordPress Plugin WPtouch version 3.4.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.3 or latest
References
https://blog.sucuri.net/2014/07/disclosure-insecure-nonce-generation-in-wptouch.html
http://packetstormsecurity.com/files/127475/Wordpress-WPTouch-Authenticated-File-Upload.html
Related Vulnerabilities
WordPress Plugin WP Shieldon-WordPress Firewall Cross-Site Scripting (1.6.3)
PHP Other Vulnerability (CVE-1999-0238)
Drupal Core 5.x Cross-Site Scripting (5.0 - 5.5)
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.5.3)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (5.0.8)