WordPress Core versions up to 6.0.2 have a security vulnerability that can be exploited if an attacker injects malicious content into the code of a plugin. This malicious content will trigger when something goes wrong when the plugin is deactivated or deleted. In most cases, the malicious content is likely to be sent as a request parameter and it will modify the error message that is displayed.