This Metasploit module exploits multiple vulnerabilities in the WordPress plugin Pixabay Images version 2.3.6. The plugin does not check the host of a provided download URL which can be used to store and execute malicious PHP code on the system.
d111cecf145c4dabb425662dffda4d1cf8b9241d370037c752f93b57412ecb27