WordPress Contact Form 7 before 1.3.3.3 allows unrestricted file upload and remote code execution by setting supported_type to php% and uploading a .php% file.
View the template here CVE-2020-12800.yaml
References:
https://github.com/amartinsec/CVE-2020-12800