WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
Use Respondus LockDown Browser and LDB Lab to prevent printing, copying, accessing other applications or browsing the web while in a testing environment.