This Metasploit module exploits an arbitrary PHP code upload in the WordPress Creative Contact Form version 0.9.7. The vulnerability allows for arbitrary file upload and remote code execution.
f67d354bf1423deeda6860a5375cc709458e085127ee4fde423e1181e6630458
WordPress / Joomla Creative Contact Form plugin versions 0.9.7 and below suffer from a remote shell upload vulnerability.
eb391ebca6e21e3d261e2f17e0d89b07a0bac8b6bed6861a21109d25042e3a13