A popular plugin for WordPress called “Product Carousel Slider & Grid Ultimate for WooCommerce” has a security vulnerability. This means that anyone with at least Contributor-level access can include and run any file on the website’s server. This could lead to unauthorized access, stealing of sensitive information, or running of malicious code. This vulnerability exists in all versions up to 1.9.10 and can be exploited by adding a specific code to the plugin’s shortcode.