WordPress Button Generator before 2.3.3 within the wow-company admin menu page allows arbitrary file inclusion with PHP extensions (as well as with data:// or http:// protocols), thus leading to cross-site request forgery and remote code execution.
View the template here CVE-2021-25052.yaml
References:
https://github.com/ARPSyndicate/cvemon