This Metasploit module exploits a file upload feature of Drag and Drop Multi File Upload - Contact Form 7 for versions prior to 1.3.4. The allowed file extension list can be bypassed by appending a %, allowing for php shells to be uploaded. No authentication is required for exploitation.
d94c9f0362d25709f05afe545bc81aff8520f8eb38e83726bf24a2463da16a0a
WordPress Drag and Drop File Upload Contact Form plugin version 1.3.3.2 suffers from a remote shell upload vulnerability.
36da7f722845fbc942179b4637fb9e3df8d66888734d49a9f4a425645863787a