WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
This is perfect for network administrators managing remote systems. For less critical stuff, like an app crash (ID 1001), you ...