A plugin called “WC Place Order Without Payment” for the blogging platform WordPress has a security flaw in versions up to 2.6.7. This means that people who are not logged in can access and run any file on the server, including files with PHP code. This can be used to get around security measures, get private information, or run code even if the file type is considered safe.