WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
EMBED <iframe src="https://archive.org/embed/monthly-ascii-1993-09" width="560" height="384" frameborder="0" webkitallowfullscreen="true" mozallowfullscreen="true ...