WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
"My website is ranked first on Google. " No such things. First, because paid ads are what are ranking first on ALL Google search engine result pages (SERPs), not websites. Also, because ...