WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
To display a tooltip, you may use Comments, Notes, Data Validation Help Text, or Screen Tips. Let us see how they work in Excel and Google Sheets.