The Pop-Up Chop Chop plugin for WordPress has a security vulnerability in versions up to 2.1.7. This means that attackers who are logged in and have contributor-level access or higher can access and run any files on the server, including PHP code. This can bypass permissions, access private information, or execute code even if only “safe” file types like images are allowed to be uploaded.