The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
https://wpscan.com/vulnerability/b12397e7-5d9b-42bf-bd31-5d3401bc4600/