WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
The extension can be downloaded from the Visual Studio Marketplace. To preview math symbols, some fonts are required, which you can either install manually or let the ...