The Vrm 360 3D Model Viewer WordPress plugin up to and including 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.
maurice vrm360