A critical WordPress plugin flaw allows threat actors to run arbitrary PHP commands, potentially taking over entire websites.
WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.