######################
# Exploit Title : Wordpress Tevolution Plugin 2.3.1 Arbitrary Shell Upload Vulnerability
# Exploit Author : xBADGIRL21
# Dork : inurl:/wp-content/plugins/Tevolution/tmplconnector
# Vendor Homepage : https://templatic.com/
# version : 2.3.1
# Tools by @MasterZombie :Shell Uploader:https://userscloud.com/eqdkxph1lmwt
######################
# [+] DESCRIPTION :
######################
# [+] The Tevolution WordPress plugin enables advanced functionality in our themes.
# [+] Some of the features it enables include custom post types, monetization options, custom fields…
# [+] An arbitrary shell upload web vulnerability has been detected in the Tevolution Plugin 2.3.1 and below.
# [+] The vulnerability allows remote attackers to upload arbitrary files within the wordpress upload directory
######################
# [+] USAGE :
######################
# 1.- Download Wordpress Tevolution Plugin Arbitrary Shell Uploader:https://userscloud.com/eqdkxph1lmwt
# 2.- Use Dork and Choose One Of the Website
# 3.- Edit The Uploader
# 4.- Upload Your File using Tamperdata : shell.php.jpg or shell.php.txt
######################
# [+] Dev!l Path :
######################
# http(s)://<wp-host>/<wp-path>/wp-content/themes/Directory/images/tmp/zombie.php
######################
# [+] Live Demo :
######################
# http://guiagronicaragua.com
# http://eventsinsuriname.com
http://localhoneymarket.2base.in/PakistanZindabad.html
http://www.zone-h.org/mirror/id/26679997
http://demo-uat.com/
http://www.zone-h.org/mirror/id/26679960











