A quick POC for arbitrary file upload vulnerability in https://www.phpzag.com/drag-and-drop-file-upload-using-jquery-and-php/.
For testing purpose (will create an Apache/PHP docker container with vuln versions of the plugin):
./docker/install.sh
You can examine the docker container with: