Security researchers have identified a vulnerability in the WordPress plugin WPtouch that allows a logged-in user to upload PHP files to the server without having administrator privileges.
The plugin has been downloaded more than 5.5 million times, but the reported vulnerability only affects versions 3.x. Website administrators using older versions (1.x and 2.x) have nothing to fear.
The popularity of this particular plugin is due to the fact that it allows the WordPress Theme to be customized and rendered on mobile devices, without any impact on the desktop version of the website.
Regarding the vulnerability, security researchers at Sucuri report that only websites that allow guest user registration are at risk.
An attacker could exploit WordPress's "admin_init" component, which is used as an authentication method to gain unrestricted access to the website, by uploading a remote shell.
He could then install PHP backdoors or other malware, and essentially gain control of the website.
To address this specific security vulnerability, users should immediately install the new version of WPtouch (3.4.3), which you can download from here.
More information about the vulnerability can be found on the Sucuri Blog.
