The WordPress ShowBiz Pro plugin version <= 1.7.1 allows arbitrary PHP file upload via the `admin-ajax.php` endpoint.This leads to unauthenticated remote code execution.
id: CVE-2015-9499
info:
name: WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Uploa
...