WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
A Linktree Clone I built in React which has Social Icons, Link Buttons, Foldouts, Headers, and a easy to use colour palette.