
WordPress Online Booking & Scheduling Calendar for WordPress by vcita Plugin <= 4.5.3 is vulnerable to a medium priority Arbitrary File Upload
Sink: Weak check only checks Content-Type, which leads to RCE system arbitrary file upload vulnerability
PoC: Change the Content-Type field to image/png and the file signature to GIF87a
