The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
https://wpscan.com/vulnerability/0be8a03e-d854-48db-bdc0-1beead3d7b91/