* Exploit Title: Wordpress Beauty Theme File Upload Vulnerability v1.0.8 * Discovery Date: 02.09.2016 * Public Disclosure Date:03.09.2016 * Vendor Homepage: http://www.yourinspirationweb.com * Exploit Author: Colette Chamberland (Wordfence) * Contact: colette@wordfence.com * Version: 1.0.8 (may affect newer versions but this was all I had) * Tested on: Wordpress 4.2.x-4.4.x Description ================================================================================ The Beauty Premium theme contains a contact form that is vulnerable to CSRF and File Upload vulnerability in the sendmail.php file. The file attachment gets uploaded to the wordpress upload directory and it is not sanitized, allowing attackers to upload harmful code. PoC ================================================================================ Google Dork inurl:themes/beauty-premium/ or detect via WPScan: