Description
WordPress Plugin WPtouch is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently e.g. upload and execute arbitrary PHP code; this could lead to total compromise of the website. WordPress Plugin WPtouch version 3.4.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.3 or latest
References
https://blog.sucuri.net/2014/07/disclosure-insecure-nonce-generation-in-wptouch.html
http://packetstormsecurity.com/files/127475/Wordpress-WPTouch-Authenticated-File-Upload.html